Law note · Mississippi

Breach notification law, notice of security breach

cite Miss. Code Ann. ยง 75-24-29(2)-(3) stage IN FORCE in force since 2011-07-01 reviewed 2026-08-28

A person who conducts business in Mississippi and whose data includes personal information must disclose a breach of security to all affected individuals without unreasonable delay, subject to completing an investigation; notification is not required if the person reasonably determines, after investigation, that the breach will not likely result in harm.

Personal information is an individual's name combined with a Social Security number, a driver's license, state identification card, or tribal identification card number, or an account or credit or debit card number with a required access credential, and excludes publicly available information lawfully made available from government records or widely distributed media; it has no biometric element.

Enacted as HB 583 (2010), effective July 1, 2011, and amended by HB 277 (2021, effective July 1, 2021), which added the tribal identification card number as a qualifying element; every other subsection, including the enforcement clause, is unchanged since 2010.

What it asks of an app

  • Disclose a breach of security to all affected Mississippi individuals without unreasonable delay, unless your investigation reasonably determines the breach will not likely result in harm.
  • Do not rely on this statute to cover a breach exposing only biometric data; its personal information definition has no biometric element.

When LexLint raises it

Declared activities: crawls_web, trains_models, deploys_chatbot, automated_outreach

Primary source: official Mississippi Legislature enrolled act text, as sent to the Governor, billstatus.ls.state.ms.us

← Back to the example  ·  Lint your app →