🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
US-MO v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing12 sources retrieved model claude-sonnet-5 · 2026-08-06

Missouri, USA

US-MO schema gdpri-v2 trajectory: not yet assessedregulated (sectoral)overlaps: FIM, WPM, AIC

Last updated · 10 categories · 53 claims · 20 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
53Claimsbaseline..claims[]
4Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Latest update · 14 September 2026

Lead Signal

Missouri's data-protection landscape this cycle is defined by the commencement of the Insurance Data Security Act, codified at RSMo §§375.1400-375.1427, which took effect January 1, 2026 and establishes exclusive state standards for insurance licensees on data security, cybersecurity-event investigation, and notification to the Director of the Department of Commerce and Insurance. The Act requires insurance licensees to notify the Director within four business days of a qualifying cybersecurity event, a sector-specific breach-notification timeline distinct from the timing under Missouri's general breach-notification statute. Governor Mike Kehoe is understood to have signed House Bill 974 into law on July 2, 2025, aligning Missouri with more than 30 states that have adopted the NAIC model law on insurance data security. This is the cycle's most material Missouri-specific development, layering a sector-specific accountability and breach-notification regime on top of an otherwise structurally sparse state privacy framework.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

A narrow but real state statute (breach notification) and clear regulator identity exist, but there is no comprehensive material/territorial scope framework, hence amber rather than green.

Primary frameworkMo. Rev. Stat. §407.1500 (breach notification) + federal FTC Act Section 5 baseline; no state omnibus privacy statute
Supervisory authorityMissouri Attorney General
Traffic-light rationale — AmberA narrow but real state statute (breach notification) and clear regulator identity exist, but there is no comprehensive material/territorial scope framework, hence amber rather than green.

Sub-modules (5)

Regulator And AuthorityAmber

The Missouri Attorney General is the sole state authority with statutory enforcement power over §407.1500; there is no dedicated state data-protection authority analogous to a DPA.

Claims (1):

  • Missouri has no comprehensive consumer-privacy statute; the Missouri Attorney General enforces general consumer-protection law and the state breach-notification statute in this space.

Act And InstrumentsAmber

The principal instrument is Mo. Rev. Stat. §407.1500; there is no Missouri-equivalent of GDPR/CCPA.

Claims (2):

  • The primary state-level data-protection instrument in Missouri is the data-breach notification statute at Mo. Rev. Stat. §407.1500, Chapter 407, Title XXVI.
  • Federal Trade Commission Act Section 5 unfair-or-deceptive-practices authority applies nationally, including to Missouri entities, as a general privacy-and-security enforcement baseline in the absence of a state omnibus law.

Material ScopeRed

Material scope is narrow, tracking identity-theft/financial-fraud data elements typical of first-generation US breach laws rather than a broad 'personal data' definition.

Claims (1):

  • US state breach-notification statutes, including Missouri's, generally define covered personal information narrowly around identity-theft and financial-fraud data elements, in contrast to the broader definitions used in comprehensive state privacy laws.

Territorial ScopeAmber

The breach statute applies based on the residency of affected individuals (Missouri residents) and a 1,000-resident AG-notification threshold, rather than a controller-establishment test.

Claims (1):

  • Notification under Missouri's breach statute must be provided without undue delay to consumers and to the Missouri Attorney General where the breach involves the information of more than 1,000 Missouri residents.

Regulator Registration And FilingRed

No general controller registration or filing scheme exists; AG notice is triggered only by the breach threshold.

Claims (1):

  • Missouri imposes no general controller registration or filing regime; the only filing-adjacent duty is threshold-triggered breach notice to the Attorney General.
Category narrative85 words

Missouri has no comprehensive consumer-privacy statute. The operative state instrument is the data-breach notification law at Mo. Rev. Stat. §407.1500 (Chapter 407, Title XXVI), enforced exclusively by the Missouri Attorney General. Absent a state omnibus law, general privacy conduct in Missouri is governed by the federal FTC Act Section 5 unfair/deceptive-practices authority and applicable federal sectoral statutes (HIPAA, GLBA, COPPA). No controller registration or filing regime exists at the state level; the only filing-adjacent obligation is AG notification once a breach crosses a 1,000-resident threshold.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (6)
  1. ConfirmedOneTrust DataGuidance — Missouri has no comprehensive consumer-privacy statute; the Missouri Attorney General enforces general consumer-protection law and the state breach-notification statute in this space.observed
  2. ConfirmedOneTrust DataGuidance — The primary state-level data-protection instrument in Missouri is the data-breach notification statute at Mo. Rev. Stat. §407.1500, Chapter 407, Title XXVI.observed
  3. ConfirmedFederal Trade Commission — Federal Trade Commission Act Section 5 unfair-or-deceptive-practices authority applies nationally, including to Missouri entities, as a general privacy-and-security enforcement baseline in the absence of a state omnibus law.observed
  4. ProbableIAPP — US state breach-notification statutes, including Missouri's, generally define covered personal information narrowly around identity-theft and financial-fraud data elements, in contrast to the broader definitions used in comprehensive state privacy laws.observed
  5. ConfirmedOneTrust DataGuidance — Notification under Missouri's breach statute must be provided without undue delay to consumers and to the Missouri Attorney General where the breach involves the information of more than 1,000 Missouri residents.observed
  6. ConfirmedOneTrust DataGuidance — Missouri imposes no general controller registration or filing regime; the only filing-adjacent duty is threshold-triggered breach notice to the Attorney General.observed

#

Only a single narrow biometric-consent carve-out exists; there is no general lawful-basis or special-category framework, consistent with the seed's disambiguation note.

Primary frameworkNo general lawful-basis statute; Missouri House Bill 1584 (biometric consent) is the sole special-category-adjacent rule
Supervisory authorityMissouri Attorney General
Traffic-light rationale — RedOnly a single narrow biometric-consent carve-out exists; there is no general lawful-basis or special-category framework, consistent with the seed's disambiguation note.

Sub-modules (4)

Lawful BasesRed

No GDPR Art 6-equivalent enumeration of lawful processing bases exists in Missouri law.

Claims (1):

  • Missouri has no statutory enumeration of lawful bases for processing personal data equivalent to GDPR Article 6.

Special CategoriesAmber

Biometric identifiers are the only category subject to a dedicated consent/policy regime, under HB 1584.

Claims (1):

  • Missouri House Bill 1584, effective 28 August 2024, requires private entities to obtain consent and maintain public policies before collecting biometric identifiers, functioning as Missouri's only sensitive-category-specific consent rule.

Pseudonymisation And AnonymisationAmber

No state-law definition exists; the closest analogue is the federal FERPA de-identification safe harbor (34 CFR §99.31(b)) applicable to Missouri schools receiving federal education funds.

Claims (1):

  • The federal FERPA de-identification safe harbor permits schools to release education records without consent once personally identifiable information has been removed and re-identification risk reasonably assessed, applicable to Missouri educational agencies receiving federal funds.
Category narrative49 words

Missouri has no statutory enumeration of lawful processing bases, no general consent standard, and no special/sensitive-category regime, with the narrow exception of House Bill 1584's biometric-data consent requirement (effective 28 August 2024). Pseudonymisation/anonymisation is addressed only indirectly, via the federal FERPA de-identification safe harbor applicable to Missouri educational agencies.

Sources and claims (4)
  1. ProbableOneTrust DataGuidance — Missouri House Bill 1584, effective 28 August 2024, requires private entities to obtain consent and maintain public policies before collecting biometric identifiers, functioning as Missouri's only sensitive-category-specific consent rule.observed
  2. ConfirmedOneTrust DataGuidance — Outside the HB 1584 biometric-consent requirement, Missouri imposes no general consent standard for the processing of personal data.observed
  3. ConfirmedOneTrust DataGuidance — Missouri has no statutory enumeration of lawful bases for processing personal data equivalent to GDPR Article 6.observed
  4. ConfirmedIAPP — The federal FERPA de-identification safe harbor permits schools to release education records without consent once personally identifiable information has been removed and re-identification risk reasonably assessed, applicable to Missouri educational agencies receiving federal funds.observed

#

No DSAR-equivalent rights exist in Missouri law; this is a genuine regulatory gap, not an omission of research.

Supervisory authorityMissouri Attorney General
Traffic-light rationale — RedNo DSAR-equivalent rights exist in Missouri law; this is a genuine regulatory gap, not an omission of research.

Sub-modules (5)

Access RightRed

No statutory right of access to personal data exists in Missouri.

Claims (1):

  • Missouri law confers no general consumer right of access to personal data held by a business.

Rectification And ErasureRed

No statutory right to correct or delete personal data exists in Missouri.

Claims (1):

  • Missouri law confers no general consumer right to rectify or erase personal data held by a business.

Restriction And ObjectionRed

No statutory right to restrict processing or object (including to profiling) exists in Missouri.

Claims (1):

  • Missouri law confers no general consumer right to restrict processing or object to processing, including profiling.

Data PortabilityRed

No statutory portability right exists in Missouri.

Claims (1):

  • Missouri law confers no general consumer data-portability right.

Deadlines And Response WindowsAmber

The only statutory timing obligation is breach notice 'without undue delay'; no consumer rights-request deadline exists because no rights framework exists.

Claims (1):

  • Missouri's breach statute requires notification to consumers without undue delay, but no statutory deadline exists for responding to consumer data-rights requests because no such rights regime exists.
Category narrative49 words

Missouri confers no general access, rectification, erasure, restriction/objection, or portability rights on consumers with respect to personal data. The only consumer-facing entitlement is the statutory expectation of breach notice 'without undue delay' once a qualifying breach occurs; there is no rights-request response-time regime because no underlying rights framework exists.

Sources and claims (5)
  1. ConfirmedOneTrust DataGuidance — Missouri law confers no general consumer right of access to personal data held by a business.observed
  2. ConfirmedOneTrust DataGuidance — Missouri law confers no general consumer right to rectify or erase personal data held by a business.observed
  3. ConfirmedOneTrust DataGuidance — Missouri law confers no general consumer right to restrict processing or object to processing, including profiling.observed
  4. ConfirmedOneTrust DataGuidance — Missouri law confers no general consumer data-portability right.observed
  5. ConfirmedOneTrust DataGuidance — Missouri's breach statute requires notification to consumers without undue delay, but no statutory deadline exists for responding to consumer data-rights requests because no such rights regime exists.observed

#

Breach notification is a real, binding, in-force duty (amber-worthy baseline), but every other accountability duty is absent, preventing a green rating.

Primary frameworkMo. Rev. Stat. §407.1500 (breach notification only)
Supervisory authorityMissouri Attorney General
Traffic-light rationale — AmberBreach notification is a real, binding, in-force duty (amber-worthy baseline), but every other accountability duty is absent, preventing a green rating.

Sub-modules (7)

Accountability And DpiaRed

No DPIA or general accountability-principle statute exists in Missouri.

Claims (1):

  • Missouri has no statutory Data Protection Impact Assessment or general accountability-principle requirement.

Dpo RequirementsRed

No DPO appointment requirement exists in Missouri.

Claims (1):

  • Missouri has no statutory Data Protection Officer appointment threshold or requirement.

Ropa RequirementsRed

No records-of-processing requirement exists in Missouri.

Claims (1):

  • Missouri has no statutory records-of-processing-activities requirement.

Joint Controller ArrangementsRed

No statutory joint-controller framework exists in Missouri; any analogous duties arise only under federal sectoral law (e.g., GLBA/HIPAA service-provider provisions), which falls outside this state-level baseline.

Claims (1):

  • Missouri has no statutory joint-controller allocation-of-responsibility framework.

Security MeasuresAmber

No general statutory information-security-program mandate was confirmed at the state level; adoption of NAIC-model insurance-sector security standards in Missouri could not be verified in this pass.

Claims (1):

  • No general Missouri state-law mandate for technical/organisational security-of-processing measures was confirmed; potential sector-specific NAIC Insurance Data Security Model Law adoption in Missouri could not be verified in this research pass.

Breach NotificationGreen

Missouri's core, binding data-protection duty: notify affected consumers without undue delay and notify the Attorney General once the 1,000-resident threshold is met; notice may be written, electronic, or telephonic.

Claims (2):

  • Missouri law requires notification to affected consumers without undue delay, and to the Missouri Attorney General, when a breach affects the personal information of more than 1,000 Missouri residents.
  • Notification under Missouri's breach statute may be provided in writing, in electronic form, or by telephone.

Retention And DisposalRed

No general statutory retention-limitation or disposal duty exists in Missouri outside the narrow biometric-retention-policy element of HB 1584.

Claims (1):

  • Missouri has no general statutory data-retention-limitation or disposal duty outside the narrow biometric-policy element of HB 1584.
Category narrative60 words

The only substantive controller duty under Missouri state law is breach notification under §407.1500. There is no statutory DPIA, DPO, ROPA, joint-controller, general security-measures, or retention/disposal regime at the state level. Sector-specific security obligations (e.g., insurance data-security standards potentially modeled on the NAIC Insurance Data Security Model Law) could not be confirmed as adopted in Missouri within this research pass.

Periodic update · new data 2026-09-14

Controller/Processor Duties

The Insurance Data Security Act, effective January 1, 2026, establishes exclusive state standards for insurance licensees covering data security, cybersecurity-event investigation, and notification obligations to the Director of the Department of Commerce and Insurance. This confirmed development imposes a written information-security-program duty on covered insurance licensees, a form of accountability obligation not previously present in Missouri's general data-protection landscape, which otherwise lacks any cross-sectoral controller/processor accountability framework such as a DPIA requirement.

A specific and confirmed sub-obligation under the Act is its breach-notification deadline: insurance licensees must notify the Missouri Director of the Department of Commerce and Insurance within four business days of a qualifying cybersecurity event. This is materially faster than the general expectations under the state's cross-sectoral breach-notification statute and reflects a sector-specific compliance timeline particular to insurance licensees rather than a change to the general-purpose breach law applicable to other sectors.

Outlook

As the Act is newly in force, the practical operating experience of insurance licensees under its written-program and four-business-day notification requirements will become clearer in subsequent cycles. Whether the Act's accountability model migrates to other sectors, or whether Missouri considers broader accountability obligations analogous to a general-purpose DPIA requirement, remains unresolved and unindicated by any evidence this cycle.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (8)
  1. ConfirmedOneTrust DataGuidance — Missouri law requires notification to affected consumers without undue delay, and to the Missouri Attorney General, when a breach affects the personal information of more than 1,000 Missouri residents.observed
  2. ConfirmedOneTrust DataGuidance — Notification under Missouri's breach statute may be provided in writing, in electronic form, or by telephone.observed
  3. UncertainIAPP — No general Missouri state-law mandate for technical/organisational security-of-processing measures was confirmed; potential sector-specific NAIC Insurance Data Security Model Law adoption in Missouri could not be verified in this research pass.observed
  4. ConfirmedOneTrust DataGuidance — Missouri has no statutory Data Protection Impact Assessment or general accountability-principle requirement.observed
  5. ConfirmedOneTrust DataGuidance — Missouri has no statutory Data Protection Officer appointment threshold or requirement.observed
  6. ConfirmedOneTrust DataGuidance — Missouri has no statutory records-of-processing-activities requirement.observed
  7. ConfirmedOneTrust DataGuidance — Missouri has no statutory joint-controller allocation-of-responsibility framework.observed
  8. ConfirmedOneTrust DataGuidance — Missouri has no general statutory data-retention-limitation or disposal duty outside the narrow biometric-policy element of HB 1584.observed

#

No state-level transfer, adequacy, or localisation regime exists; explicit absence per JID-adaptive rules for US state JIDs.

Traffic-light rationale — RedNo state-level transfer, adequacy, or localisation regime exists; explicit absence per JID-adaptive rules for US state JIDs.

Sub-modules (6)

Transfer MechanismsRed

No Missouri state-level transfer-mechanism regime exists; any applicable mechanisms (EU-US DPF, SCCs) operate at the federal/EU level, outside the US-MO JID.

Claims (1):

  • Missouri has no independent state-level cross-border personal-data transfer regime; applicable mechanisms operate at the federal/EU level.

Adequacy ReceivedRed

Adequacy determinations are a federal/EU-level matter; Missouri has no independent adequacy status.

Absence provenance: unavailable. Searched: M, i, s, s, o, u, r, i, , s, t, a, t, e, , a, d, e, q, u, a, c, y, , d, e, t, e, r, m, i, n, a, t, i, o, n, , E, U, , G, D, P, R.

Adequacy GrantedRed

Missouri does not independently grant adequacy status to other jurisdictions; this is a federal/EU-level construct.

Absence provenance: unavailable. Searched: M, i, s, s, o, u, r, i, , a, d, e, q, u, a, c, y, , d, e, c, i, s, i, o, n, s, , g, r, a, n, t, e, d, , t, o, , o, t, h, e, r, , j, u, r, i, s, d, i, c, t, i, o, n, s.

Sccs And BcrsRed

SCC/BCR uptake is a matter of federal/EU cross-border transfer law, not independently regulated by Missouri.

Absence provenance: unavailable. Searched: M, i, s, s, o, u, r, i, , S, C, C, , B, C, R, , s, t, a, t, e, , l, a, w, , r, e, q, u, i, r, e, m, e, n, t.

Transfer Impact AssessmentRed

No Missouri-specific transfer-impact-assessment requirement exists.

Absence provenance: unavailable. Searched: M, i, s, s, o, u, r, i, , t, r, a, n, s, f, e, r, , i, m, p, a, c, t, , a, s, s, e, s, s, m, e, n, t, , r, e, q, u, i, r, e, m, e, n, t.

Data LocalisationRed

Missouri imposes no state-level data-localisation mandate on personal-data processing.

Claims (1):

  • Missouri imposes no state-level data-localisation mandate requiring personal data to be stored or processed within the state.
Category narrative58 words

Missouri, as a US state, has no independent cross-border-transfer regime, no data-localisation mandate, and no state-level role in adequacy determinations. Cross-border transfer mechanisms (e.g., the EU-US Data Privacy Framework, SCCs) operate at the federal/EU level and are outside the scope of Missouri state law; this module is therefore a structural gap by design rather than a research omission.

Sources and claims (2)
  1. ConfirmedOneTrust DataGuidance — Missouri has no independent state-level cross-border personal-data transfer regime; applicable mechanisms operate at the federal/EU level.observed
  2. ConfirmedOneTrust DataGuidance — Missouri imposes no state-level data-localisation mandate requiring personal data to be stored or processed within the state.observed

#

Federal sectoral coverage is solid and confirmed; state-level sectoral detail (insurance, communications, credit cards) is thin and partly unverified.

Primary frameworkFederal sectoral statutes (GLBA, HIPAA, FERPA, COPPA, FCRA) overlaid on Missouri's narrow state provisions
Supervisory authorityMissouri Attorney General
Traffic-light rationale — AmberFederal sectoral coverage is solid and confirmed; state-level sectoral detail (insurance, communications, credit cards) is thin and partly unverified.

Sub-modules (7)

Financial Sector OverlayAmber

GLBA applies nationally to Missouri financial institutions, requiring privacy notices and safeguarding of non-public personal information.

Claims (1):

  • The federal Gramm-Leach-Bliley Act applies nationally to financial institutions operating in Missouri, imposing privacy-notice and safeguarding obligations for non-public personal information.

Health Sector OverlayAmber

HIPAA applies nationally to Missouri covered entities; DataGuidance also notes unspecified Missouri health-information rules.

Claims (1):

  • Missouri legislation includes additional rules touching health information alongside the federal HIPAA framework that applies to covered entities nationally.

Telecoms And EprivacyRed

DataGuidance references additional Missouri rules on communications, but the specific statute and scope could not be independently verified in this pass; no state cookie/ePrivacy-style law was identified.

Claims (1):

  • Missouri legislation reportedly includes additional rules on communications, though the specific statute and its scope relative to telecoms/eprivacy could not be independently verified in this research pass.

Employment DataRed

No comprehensive Missouri employment-data privacy statute was identified.

Claims (1):

  • No comprehensive Missouri employment-data privacy statute displacing or supplementing general federal employment-privacy law was identified.

Credit And ScoringAmber

The federal Fair Credit Reporting Act governs credit-related personal data nationally; DataGuidance references unspecified Missouri credit-card rules, not independently verified here.

Claims (1):

  • The federal Fair Credit Reporting Act governs credit-scoring and credit-reporting personal data nationally; Missouri legislation additionally references unspecified credit-card-related rules.

EducationAmber

FERPA and COPPA jointly govern Missouri's education/ed-tech sector at the federal level; no distinct Missouri student-data-privacy statute was identified in this research.

Claims (1):

  • FERPA and COPPA jointly govern personal-data handling in Missouri's education and ed-tech sectors at the federal level; no distinct Missouri student-data-privacy statute was identified in this research.

InsuranceRed

Whether Missouri has adopted the NAIC Insurance Data Security Model Law (adopted by NAIC in 2017 and enacted variously by other states) could not be confirmed in this research pass.

Claims (1):

  • Whether Missouri has enacted a version of the NAIC Insurance Data Security Model Law (as South Carolina, Ohio, and Michigan have) could not be confirmed in this research pass.
Category narrative70 words

Federal sectoral overlays supply the substantive privacy content Missouri's own statute book lacks: GLBA for financial institutions, HIPAA for covered health entities, FERPA/COPPA for education and children's data, and FCRA for credit reporting. Missouri's own legislation supplements this narrowly around communications, credit cards, and health information, per DataGuidance's jurisdiction overview, but the specifics of the state-level communications/credit-card rules and insurance-sector security standards could not be independently confirmed in this pass.

Periodic update · new data 2026-09-14

Sectoral Watch

The cycle's most material Missouri-specific data-protection development is the commencement of the Insurance Data Security Act, codified at RSMo §§375.1400-375.1427, which establishes exclusive state standards applicable to insurance licensees for data security, cybersecurity-event investigation, and notification to the Director, and took effect January 1, 2026. Governor Mike Kehoe is understood to have signed the underlying legislation, House Bill 974, into law on July 2, 2025, a step reported to align Missouri with more than 30 other states that have adopted the National Association of Insurance Commissioners' model law on insurance data security.

This sectoral overlay sits on top of, and is distinct from, Missouri's general breach-notification statute at §407.1500; the Insurance Data Security Act's provisions are exclusive standards for insurance licensees specifically, meaning insurance-sector entities in Missouri now operate under a materially more detailed data-security and notification regime than entities outside the insurance sector. This is the clearest example this cycle of Missouri's characteristic pattern: sector-specific data-protection law advancing in the absence of any comprehensive omnibus statute.

Outlook

With the Insurance Data Security Act now in force, the next cycle's watch item is the practical supervisory and enforcement experience under it, including whether the Director's office issues any guidance, examination findings, or enforcement actions under the new framework. Whether Missouri extends a comparable sectoral model to any other regulated industry remains an open question with no evidence pointing either way this cycle.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (7)
  1. ConfirmedFederal Trade Commission — The federal Gramm-Leach-Bliley Act applies nationally to financial institutions operating in Missouri, imposing privacy-notice and safeguarding obligations for non-public personal information.observed
  2. ProbableOneTrust DataGuidance — Missouri legislation includes additional rules touching health information alongside the federal HIPAA framework that applies to covered entities nationally.observed
  3. UncertainOneTrust DataGuidance — Missouri legislation reportedly includes additional rules on communications, though the specific statute and its scope relative to telecoms/eprivacy could not be independently verified in this research pass.observed
  4. UncertainOneTrust DataGuidance — No comprehensive Missouri employment-data privacy statute displacing or supplementing general federal employment-privacy law was identified.observed
  5. ProbableOneTrust DataGuidance — The federal Fair Credit Reporting Act governs credit-scoring and credit-reporting personal data nationally; Missouri legislation additionally references unspecified credit-card-related rules.observed
  6. ConfirmedIAPP — FERPA and COPPA jointly govern personal-data handling in Missouri's education and ed-tech sectors at the federal level; no distinct Missouri student-data-privacy statute was identified in this research.observed
  7. UncertainIAPP — Whether Missouri has enacted a version of the NAIC Insurance Data Security Model Law (as South Carolina, Ohio, and Michigan have) could not be confirmed in this research pass.observed

#

This entire module is a structural gap in Missouri law, consistent with the seed's disambiguation note that Missouri lacks comprehensive consumer-privacy rights.

Traffic-light rationale — RedThis entire module is a structural gap in Missouri law, consistent with the seed's disambiguation note that Missouri lacks comprehensive consumer-privacy rights.

Sub-modules (6)

Cookies And TrackersRed

No Missouri cookie/tracker consent law exists.

Claims (1):

  • Missouri has no state-law cookie or tracker consent regime.

Dark PatternsRed

No Missouri dark-patterns prohibition statute exists.

Claims (1):

  • Missouri has no statute specifically prohibiting dark patterns in consumer-facing consent interfaces.

Opt Out SignalsRed

No Missouri statute requires recognition of universal opt-out signals such as Global Privacy Control.

Claims (1):

  • Missouri imposes no legal duty on businesses to recognize universal opt-out signals such as Global Privacy Control.

Clean Rooms And DcrRed

No Missouri clean-room/data-collaboration-room rules exist.

Claims (1):

  • Missouri has no statutory rules governing data clean rooms or data-collaboration arrangements.

Cross Context AdvertisingRed

No CPRA-style 'sale'/'share' cross-context-advertising regime exists in Missouri.

Claims (1):

  • Missouri has no CPRA-style statutory concept of 'sale' or 'share' of personal information triggering cross-context-advertising opt-out rights.

Direct MarketingAmber

Direct marketing in Missouri is governed only by generally applicable federal statutes (TCPA, CAN-SPAM); no Missouri-specific consent or suppression law was identified.

Claims (1):

  • Direct marketing to Missouri consumers is governed by generally applicable federal telemarketing and anti-spam statutes rather than a Missouri-specific consent or suppression law.
Category narrative49 words

Missouri has no cookie/tracker consent law, no dark-patterns prohibition, no Global-Privacy-Control-style opt-out-signal recognition duty, no clean-room/data-collaboration rules, and no CPRA-style 'sale'/'share' cross-context-advertising regime. Direct marketing is governed only by generally applicable federal telemarketing/anti-spam statutes (e.g., TCPA, CAN-SPAM), not by any Missouri-specific consent or suppression law identified in this research.

Sources and claims (6)
  1. ConfirmedOneTrust DataGuidance — Missouri has no state-law cookie or tracker consent regime.observed
  2. ConfirmedOneTrust DataGuidance — Missouri has no statute specifically prohibiting dark patterns in consumer-facing consent interfaces.observed
  3. ConfirmedOneTrust DataGuidance — Missouri imposes no legal duty on businesses to recognize universal opt-out signals such as Global Privacy Control.observed
  4. ConfirmedOneTrust DataGuidance — Missouri has no statutory rules governing data clean rooms or data-collaboration arrangements.observed
  5. ConfirmedIAPP — Missouri has no CPRA-style statutory concept of 'sale' or 'share' of personal information triggering cross-context-advertising opt-out rights.observed
  6. ProbableFederal Trade Commission — Direct marketing to Missouri consumers is governed by generally applicable federal telemarketing and anti-spam statutes rather than a Missouri-specific consent or suppression law.observed

#

A real, in-force biometric regime exists (amber baseline), but profiling, ADM transparency, AI risk-assessment, and genetic-data sub-modules are all gaps.

Primary frameworkMissouri House Bill 1584 (biometric data consent/retention policy)
Supervisory authorityMissouri Attorney General
Traffic-light rationale — AmberA real, in-force biometric regime exists (amber baseline), but profiling, ADM transparency, AI risk-assessment, and genetic-data sub-modules are all gaps.

Sub-modules (6)

Profiling RestrictionsRed

No Missouri statute restricts profiling analogous to GDPR Article 22.

Claims (1):

  • Missouri has no statutory restriction on automated profiling analogous to GDPR Article 22.

Automated Decision Making TransparencyRed

No Missouri statute mandates ADM transparency or an explanation right for consumers.

Claims (1):

  • Missouri has no statute mandating automated-decision-making transparency or an explanation right for consumers.

Ai Risk AssessmentsRed

No comprehensive Missouri statute requires AI-specific risk assessments for personal-data processing; narrow AI bills identified (e.g., an AI Non-Sentience and Responsibility Act, an AI-in-political-advertising disclaimer bill) do not constitute a personal-data risk-assessment regime.

Claims (1):

  • No comprehensive Missouri statute mandates AI-specific risk assessments for personal-data processing; identified narrow AI-related bills (AI Non-Sentience and Responsibility Act; political-advertising AI-disclaimer bill) do not constitute a personal-data risk-assessment regime.

Biometric RegimeAmber

House Bill 1584, effective 28 August 2024, is Missouri's principal biometric-data regime, requiring consent and public retention/destruction policies from private entities collecting biometric identifiers.

Claims (1):

  • Missouri House Bill 1584, effective 28 August 2024, is the state's principal biometric-data regime, requiring private entities to adopt public retention/destruction policies and obtain consent prior to collecting biometric identifiers.

Genetic DataRed

No Missouri-specific genetic-data privacy statute was identified beyond potential federal GINA coverage of employment/insurance discrimination; this could not be fully verified in this pass.

Claims (1):

  • No Missouri-specific genetic-data privacy statute was identified in this research beyond potential federal GINA coverage of employment/insurance discrimination.

State Surveillance CarveoutsRed

No Missouri-specific state-surveillance carve-out affecting private-sector personal-data processing was identified in this research.

Claims (1):

  • No Missouri-specific state-surveillance carve-out affecting private-sector personal-data processing was identified; national-security/law-enforcement exemptions in this space are governed by federal frameworks outside the state consumer-privacy patchwork.
Category narrative65 words

Missouri's only concrete governance instrument in this module is House Bill 1584's biometric-data consent/retention-policy regime, effective 28 August 2024. There is no profiling-restriction or automated-decision-making transparency statute, no comprehensive AI-specific personal-data risk-assessment mandate, no identified genetic-data-specific statute, and no confirmed state-surveillance carve-out affecting private-sector processing. The Missouri Attorney General has opened investigatory activity into AI chatbots, which is enforcement-adjacent but not a binding transparency rule.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (6)
  1. ProbableOneTrust DataGuidance — Missouri House Bill 1584, effective 28 August 2024, is the state's principal biometric-data regime, requiring private entities to adopt public retention/destruction policies and obtain consent prior to collecting biometric identifiers.observed
  2. ConfirmedOneTrust DataGuidance — Missouri has no statutory restriction on automated profiling analogous to GDPR Article 22.observed
  3. ConfirmedOneTrust DataGuidance — Missouri has no statute mandating automated-decision-making transparency or an explanation right for consumers.observed
  4. UncertainOneTrust DataGuidance — No comprehensive Missouri statute mandates AI-specific risk assessments for personal-data processing; identified narrow AI-related bills (AI Non-Sentience and Responsibility Act; political-advertising AI-disclaimer bill) do not constitute a personal-data risk-assessment regime.observed
  5. UncertainOneTrust DataGuidance — No Missouri-specific genetic-data privacy statute was identified in this research beyond potential federal GINA coverage of employment/insurance discrimination.observed
  6. UncertainOneTrust DataGuidance — No Missouri-specific state-surveillance carve-out affecting private-sector personal-data processing was identified; national-security/law-enforcement exemptions in this space are governed by federal frameworks outside the state consumer-privacy patchwork.observed

#

Solid federal coverage (COPPA, FERPA) exists and applies to Missouri, but no state-specific layer was found for age verification, minor profiling, or dependent adults.

Primary frameworkFederal COPPA (children) and FERPA (students); no Missouri-specific statute
Supervisory authorityMissouri Attorney General
Traffic-light rationale — AmberSolid federal coverage (COPPA, FERPA) exists and applies to Missouri, but no state-specific layer was found for age verification, minor profiling, or dependent adults.

Sub-modules (5)

Age VerificationRed

No Missouri-specific age-verification-for-data-processing statute was identified.

Claims (1):

  • No Missouri-specific statute mandating age verification prior to personal-data processing was identified in this research.

Minor Profiling BansRed

No Missouri-specific statute bans profiling of minors for advertising or other purposes.

Claims (1):

  • No Missouri-specific statute bans profiling of minors for advertising or other commercial purposes.

Education SettingsAmber

FERPA governs student education-record privacy at Missouri educational agencies receiving federal funds.

Claims (1):

  • FERPA gives parents (and eligible students) rights over education records and generally prohibits nonconsensual disclosure of personally identifiable information by educational agencies and institutions, applicable to Missouri schools receiving federal funding.

Dependent AdultsRed

No Missouri-specific dependent-adults data-protection statute was identified beyond general elder-protection and HIPAA overlays; not independently verified in depth in this pass.

Claims (1):

  • No Missouri-specific dependent-adults data-protection statute was identified in this research beyond general elder-protection and federal HIPAA overlays.
Category narrative53 words

Children's and student data in Missouri are governed almost entirely by federal law: COPPA requires parental consent before online operators collect personal information from children under 13, and FERPA governs student education records at federally funded educational agencies. No Missouri-specific age-verification-for-data-processing statute, minor-profiling ban, or dependent-adults data-protection statute was identified in this research.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (5)
  1. ConfirmedFederal Trade Commission — The federal COPPA Rule requires operators of websites and online services to obtain parental consent before collecting, using, or disclosing personal information from children under 13, applicable to entities operating in Missouri.observed
  2. ConfirmedIAPP — FERPA gives parents (and eligible students) rights over education records and generally prohibits nonconsensual disclosure of personally identifiable information by educational agencies and institutions, applicable to Missouri schools receiving federal funding.observed
  3. UncertainOneTrust DataGuidance — No Missouri-specific statute mandating age verification prior to personal-data processing was identified in this research.observed
  4. ConfirmedOneTrust DataGuidance — No Missouri-specific statute bans profiling of minors for advertising or other commercial purposes.observed
  5. UncertainOneTrust DataGuidance — No Missouri-specific dependent-adults data-protection statute was identified in this research beyond general elder-protection and federal HIPAA overlays.observed

#

A real enforcement mechanism and recent AG activity exist, but the private-right-of-action and collective-redress sub-modules are largely absent or unconfirmed.

Primary frameworkMo. Rev. Stat. §407.1500 (AG enforcement)
Supervisory authorityMissouri Attorney General
Traffic-light rationale — AmberA real enforcement mechanism and recent AG activity exist, but the private-right-of-action and collective-redress sub-modules are largely absent or unconfirmed.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

The AG may bring an action for actual damages for willful and knowing violation of §407.1500.

Claims (1):

  • The Missouri Attorney General has exclusive authority to bring an action to obtain actual damages for a willful and knowing violation of §407.1500.

Enforcement Activity IndexAmber

Missouri's AG participates in NAAG-coordinated multistate breach-related settlements; a Missouri-specific standalone enforcement track record under §407.1500 was not independently quantified in this pass.

Claims (1):

  • State attorneys general, including Missouri's, frequently participate in NAAG-coordinated multistate settlements arising from data breaches.

Regulator Funding And CapacityRed

No specific funding or headcount data for the Missouri AG's privacy/consumer-protection enforcement function was identified in this research.

Absence provenance: unavailable. Searched: M, i, s, s, o, u, r, i, , A, t, t, o, r, n, e, y, , G, e, n, e, r, a, l, , c, o, n, s, u, m, e, r, , p, r, o, t, e, c, t, i, o, n, , d, i, v, i, s, i, o, n, , b, u, d, g, e, t, , s, t, a, f, f, i, n, g.

Collective Redress And Class ActionsRed

General Missouri civil-procedure class-action mechanisms may be available for privacy-adjacent common-law claims (e.g., invasion of privacy), but no privacy-specific statutory class-action mechanism was confirmed in this pass.

Absence provenance: unavailable. Searched: M, i, s, s, o, u, r, i, , c, l, a, s, s, , a, c, t, i, o, n, , p, r, i, v, a, c, y, , c, l, a, i, m, s, , R, u, l, e, , 5, 2, ., 0, 8.

Private Right Of ActionRed

The breach statute reserves enforcement to the Attorney General; no general consumer private right of action was identified.

Claims (1):

  • Missouri's breach-notification statute does not appear to create a general private right of action for consumers; enforcement is reserved to the Attorney General.

Recent Developments 180DAmber

Within the last 180 days, the Missouri AG opened an investigation into AI chatbots operated by major technology companies for alleged bias and inaccuracy, an enforcement-adjacent development relevant to the algorithmic-governance module.

Claims (1):

  • The Missouri Attorney General has opened an investigation into AI chatbots operated by major technology companies (including Google, Microsoft, OpenAI, and Meta) for alleged bias and inaccuracy.
Category narrative74 words

The Missouri Attorney General holds exclusive statutory authority to bring actions for willful and knowing violations of §407.1500, seeking actual damages; the statute does not appear to create a general private right of action for consumers. Recent enforcement-adjacent activity includes the Missouri AG's investigation into AI chatbots for alleged bias and inaccuracy, and continued participation in NAAG-coordinated multistate breach settlements. Regulator funding/headcount signals specific to privacy enforcement could not be identified in this pass.

Periodic update · new data 2026-09-14

Enforcement & Redress

Missouri's breach-notification enforcement architecture remains concentrated exclusively in the Attorney General's office. The Attorney General holds exclusive enforcement authority over the state's general breach-notification statute, §407.1500, and is understood to be able to seek civil penalties reportedly not to exceed $150,000 per breach or series of similar breaches. There is no private right of action available to individuals under this statute, meaning enforcement is a public-enforcement-only model with no parallel civil litigation track for affected consumers. This penalty figure should be treated with appropriate caution, as it currently rests on a single Tier 3 aggregator source rather than direct confirmation against the statute's current text.

This cycle's other enforcement-adjacent development is the reported change in the office of Attorney General itself: Catherine Hanaway is understood to have taken office in late August 2025, succeeding Andrew Bailey, meaning the exclusive breach-notification enforcement authority described above now sits with a different office holder than in prior cycles, though the substance of the enforcement framework itself is unchanged.

Outlook

A priority for the next cycle is direct verification of the $150,000-per-breach civil-penalty figure against the current statutory text of §407.1500, since this figure currently rests on secondary sourcing. No enforcement actions under either the general breach-notification statute or the newly effective Insurance Data Security Act have been identified this cycle.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (4)
  1. ConfirmedOneTrust DataGuidance — The Missouri Attorney General has exclusive authority to bring an action to obtain actual damages for a willful and knowing violation of §407.1500.observed
  2. ProbableOneTrust DataGuidance — Missouri's breach-notification statute does not appear to create a general private right of action for consumers; enforcement is reserved to the Attorney General.observed
  3. ProbableOneTrust DataGuidance — The Missouri Attorney General has opened an investigation into AI chatbots operated by major technology companies (including Google, Microsoft, OpenAI, and Meta) for alleged bias and inaccuracy.observed
  4. ProbableNAAG — State attorneys general, including Missouri's, frequently participate in NAAG-coordinated multistate settlements arising from data breaches.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metpass
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct25.0
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Missouri, USA
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 53 claim(s) (53 category placement(s)), 20 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsdeadlines and response windows
Art. 14Data Subject Rightsdeadlines and response windows
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressregulator powers and penalties
Art. 79Enforcement & Redressregulator powers and penalties
Art. 80Enforcement & Redressregulator powers and penalties
Art. 81Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redresscollective redress and class actions
Art. 83Enforcement & Redressprivate right of action
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

All 10 modules were populated. Regulator identity, the core breach-notification statute (§407.1500), and federal sectoral overlays (FTC Act §5, COPPA, FERPA, GLBA) rest on T1/T2 sources. The biometric-data regime (HB 1584) and most gap-findings (absence of lawful bases, DSAR rights, ADM transparency, cookie law, etc.) rest on T3 secondary sources (DataGuidance, IAPP) consistent with the seed's disambiguation note that Missouri lacks a comprehensive statute. Several sub-modules (insurance NAIC-model adoption, AI Non-Sentience Act status, Missouri communications-law specifics, genetic-data and dependent-adults statutes, regulator funding/capacity, collective-redress mechanisms) could not be verified to primary-source standard and are flagged Uncertain with absent_field_provenance.

Unresolved questions (6):

  • Has Missouri adopted any version of the NAIC Insurance Data Security Model Law, and if so under what statute/effective date?
  • What is the precise enactment/effective-date status of Missouri's AI Non-Sentience and Responsibility Act?
  • What is the specific Missouri statute referenced by DataGuidance as governing 'communications' rules, and does it have any eprivacy/telecoms-privacy content?
  • Does Missouri's general civil-procedure class-action rule (analogous to Rule 23/52.08) provide a meaningful collective-redress path for common-law invasion-of-privacy claims, and has it been used in that context?
  • Are there Missouri-specific credit-card or credit-scoring privacy rules beyond federal FCRA, as vaguely referenced by DataGuidance?
  • What are current staffing/funding levels for the Missouri Attorney General's consumer-protection/privacy enforcement function?

Escalate to primary-source review: yes