{
 "jurisdiction_id": "US-MS",
 "jurisdiction": "United States – Mississippi",
 "url": "https://dataprotection.gi/jurisdictions/united-states-mississippi/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-06",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 23,
  "sub_modules": 57,
  "source_register": 15
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "amber",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-mississippi/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "A clear sectoral/enforcement baseline exists (FTC Act + MCPA + breach law) but there is no comprehensive material-scope instrument, hence amber rather than green.",
   "claims": [
    {
     "statement": "The Federal Trade Commission Act Section 5 provides general unfair/deceptive-practices privacy enforcement authority applicable nationally, including in Mississippi.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Federal Trade Commission",
     "source_url": "https://www.ftc.gov/about-ftc/bureaus-offices/bureau-consumer-protection",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "Mississippi has enacted its own general consumer-protection statute, the Mississippi Consumer Protection Act, Miss. Code Ann. §75-24-1 et seq., which the Mississippi Attorney General enforces for unfair or deceptive trade practices.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "California Attorney General (multistate filing)",
     "source_url": "https://oag.ca.gov/system/files/attachments/press-docs/Boston%20final%20judgment.pdf",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "Mississippi has no enacted comprehensive consumer-privacy statute; a 2025 Senate bill for a Mississippi Consumer Data Privacy Act died without passage, following a similar failed 2023 attempt.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/mississippi-senate-bill-consumer-data-privacy-act-dies",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "A separate Mississippi Consumer Data Protection Act bill was referred to committee in the 2025 session as a distinct legislative attempt, indicating recurring but unsuccessful legislative interest in comprehensive privacy regulation.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/mississippi-bill-consumer-data-protection-act-was",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "red",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-mississippi/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "No comprehensive lawful-basis, consent, special-category, or anonymisation regime exists under Mississippi state law.",
   "claims": [
    {
     "statement": "Mississippi has not enacted a comprehensive consumer-privacy statute and therefore has no codified lawful-basis, consent, or special-category framework analogous to GDPR Articles 6, 7, and 9.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/mississippi-senate-bill-consumer-data-privacy-act-dies",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "red",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-mississippi/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "No state-level DSAR framework, deadlines, or portability right exists.",
   "claims": [
    {
     "statement": "Mississippi does not confer a general consumer right of access, correction, deletion, restriction, objection, or portability over personal data by statute; such rights exist in the state only through incidental application of federal sectoral law.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/mississippi-senate-bill-consumer-data-privacy-act-dies",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "amber",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-mississippi/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Breach notification is a live, in-force obligation (amber-worthy positive finding), but accountability/DPIA/DPO/ROPA/retention sub-modules are genuine gaps (red).",
   "claims": [
    {
     "statement": "Mississippi has a data-breach notification law that requires breached entities to notify Mississippi residents who may be affected by a breach of security.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "NAAG",
     "source_url": "https://www.naag.org/issues/consumer-protection/consumer-protection-101/privacy/data-breaches/",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "The Mississippi Attorney General's office has indicated it is best practice for breached entities to notify the AG's office quickly following a security breach, and a company with an existing security breach policy may satisfy Mississippi's breach requirements automatically.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/mississippi-ag-best-to-notify-us-quickly-of-a-breach",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "red",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-mississippi/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "No state-level transfer mechanism, adequacy determination, or localisation rule exists; this is a structural gap common to all non-omnibus U.S. states.",
   "claims": [
    {
     "statement": "Mississippi has not enacted any state-specific cross-border data transfer mechanism, adequacy framework, or data-localisation requirement; this domain is governed entirely by counterpart jurisdictions' own transfer rules and by whatever federal sectoral law applies, none of which is Mississippi-specific.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/mississippi-senate-bill-consumer-data-privacy-act-dies",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-mississippi/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Federal sectoral overlays (HIPAA/GLBA/COPPA) are well-established and apply in full force; state-level sectoral overlays beyond breach law and the contested Social Media Safety Act are largely absent or unconfirmed.",
   "claims": [
    {
     "statement": "The Gramm-Leach-Bliley Act imposes an affirmative and continuing obligation on financial institutions to respect customer privacy and protect the security and confidentiality of non-public personal information, and this obligation applies to financial institutions operating in Mississippi absent a stricter state overlay.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/naic-releases-insurance-data-security-model-law/",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "HIPAA does not preempt state privacy laws for covered entities, and where both state and federal requirements exist the stricter privacy protection applies; Mississippi has not enacted medical-privacy protections stricter than HIPAA.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/us-federal-privacy-preemption-part-1-history-of-federal-preemption-of-stricter-state-laws",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "Mississippi is referenced among states with insurance-sector privacy provisions tied to the 1992 NAIC Insurance Information and Privacy Protection Model Act, but confirmation that Mississippi has separately adopted the 2017 NAIC Insurance Data Security Model Law could not be obtained in this research pass.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/legal-research/naic-insurance-information-and-privacy-0",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "red",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-mississippi/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "No adtech-specific statute exists at the state level; only general UDAP coverage applies.",
   "claims": [
    {
     "statement": "Mississippi has no comprehensive privacy statute and consequently no cookie/tracker consent, dark-pattern, opt-out-signal, clean-room, cross-context-advertising, or direct-marketing-specific privacy regime; adtech practices are reachable only via general federal and state unfair/deceptive-practices authority.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/mississippi-senate-bill-consumer-data-privacy-act-dies",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "red",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-mississippi/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "No state-level ADM transparency, AI risk-assessment, biometric, or genetic-data regime exists; this module is a genuine gap.",
   "claims": [
    {
     "statement": "Mississippi has not enacted profiling-restriction, ADM-transparency, or AI-specific risk-assessment legislation comparable to GDPR Article 22 or state omnibus analogues such as Colorado's algorithmic-discrimination law.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/mississippi-senate-bill-consumer-data-privacy-act-dies",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "Mississippi is not among the small set of U.S. states (Illinois, Texas, Washington) with freestanding biometric-privacy statutes.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/retrospective-2024-in-state-sectoral-privacy-law-and-ai-law",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-mississippi/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "A live, contested state statute exists (age_verification) with active federal appellate litigation and no final resolution, plus federal COPPA coverage; other sub-modules (parental_consent beyond COPPA, minor_profiling_bans, education_settings, dependent_adults) are gaps.",
   "claims": [
    {
     "statement": "The Mississippi Social Media Safety Act requires covered social-media platforms to verify users' ages and implement measures designed to reduce minors' exposure to harmful online interactions.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/netchoice-v-fitch-round-two-and-consequences-for-online-anonymity",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "NetChoice's second challenge to the Mississippi Social Media Safety Act returned to the U.S. Court of Appeals for the Fifth Circuit after Mississippi appealed a federal district court's injunction against enforcement, with oral argument held in early February 2026.",
     "regulatory_stage": "proposed",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/netchoice-v-fitch-round-two-and-consequences-for-online-anonymity",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "The Fifth Circuit and other federal courts have appeared inclined to hold Mississippi's and other states' age-verification requirements constitutional, though a Justice Kavanaugh concurrence in an earlier stage of related litigation suggested NetChoice had shown a likelihood of success on the merits of a First Amendment challenge.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "FTC (workshop materials)",
     "source_url": "https://www.ftc.gov/system/files/ftc_gov/pdf/Amelia-Vance-Age-Verification.pdf",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "The Children's Online Privacy Protection Act requires website operators and apps to provide notice of data-collection activities and obtain verifiable parental consent before collecting personal information from children under 13, and this federal requirement applies fully within Mississippi.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Federal Trade Commission",
     "source_url": "https://www.ftc.gov/business-guidance/privacy-security",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "amber",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-mississippi/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Enforcement infrastructure (AG + FTC) is real and active, with a significant live appellate matter, but a comprehensive privacy-enforcement regime, private right of action, and collective-redress specifics remain unconfirmed or absent.",
   "claims": [
    {
     "statement": "The Mississippi Attorney General has sought civil penalties of up to $10,000 per violation under the Mississippi Consumer Protection Act in prior litigation, illustrating the statute's available remedies for unfair or deceptive practices.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "California Attorney General (multistate filing)",
     "source_url": "https://oag.ca.gov/system/files/attachments/press-docs/Boston%20final%20judgment.pdf",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "The FTC has enforcement or administrative responsibilities under more than 80 federal consumer-protection laws, providing a broad concurrent federal enforcement layer applicable in Mississippi alongside state AG authority.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Federal Trade Commission",
     "source_url": "https://www.ftc.gov/system/files/ftc_gov/pdf/p238400_ftc_collaboration_act_report.pdf",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "Mississippi's most prominent recent privacy-adjacent enforcement activity is its defense of the Social Media Safety Act against NetChoice's constitutional challenge, rather than a traditional data-protection enforcement action.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/netchoice-v-fitch-round-two-and-consequences-for-online-anonymity",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "The Fifth Circuit heard oral arguments for the second time in NetChoice v. Fitch in early February 2026, concerning Mississippi's child social-media age-verification law, with the case's procedural history described as increasingly complicated.",
     "regulatory_stage": "proposed",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/netchoice-v-fitch-round-two-and-consequences-for-online-anonymity",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  }
 ]
}