🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
US-MS · run data-protection-2026-08-06 v13-gdpri-1.0.0
content: ai_generated 15 sources retrieved model claude-sonnet-5 ·

United States – Mississippi

US-MS schema gdpri-v2 trajectory: not recordedregulated (sectoral)overlaps: FIM, WPM

Last updated · 10 categories · 23 claims · 15 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
23Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

A clear sectoral/enforcement baseline exists (FTC Act + MCPA + breach law) but there is no comprehensive material-scope instrument, hence amber rather than green.

Primary frameworkFederal Trade Commission Act, Section 5 (15 U.S.C. §45) + Mississippi Consumer Protection Act (Miss. Code Ann. §75-24-1 et seq.) + Mississippi data-breach notification statute
Supervisory authorityMississippi Attorney General
Traffic-light rationale — AmberA clear sectoral/enforcement baseline exists (FTC Act + MCPA + breach law) but there is no comprehensive material-scope instrument, hence amber rather than green.

Sub-modules (5)

Regulator And AuthorityAmber

The Mississippi Attorney General enforces the Mississippi Consumer Protection Act and coordinates on breach matters; the FTC exercises concurrent federal Section 5 authority.

Claims (2):

  • The Federal Trade Commission Act Section 5 provides general unfair/deceptive-practices privacy enforcement authority applicable nationally, including in Mississippi.
  • Mississippi has enacted its own general consumer-protection statute, the Mississippi Consumer Protection Act, Miss. Code Ann. §75-24-1 et seq., which the Mississippi Attorney General enforces for unfair or deceptive trade practices.

Act And InstrumentsAmber

Instruments are FTC Act §5, MCPA §75-24-1 et seq., and a stand-alone breach-notification statute; no omnibus privacy act exists.

Claims (2):

  • Mississippi has no enacted comprehensive consumer-privacy statute; a 2025 Senate bill for a Mississippi Consumer Data Privacy Act died without passage, following a similar failed 2023 attempt.
  • A separate Mississippi Consumer Data Protection Act bill was referred to committee in the 2025 session as a distinct legislative attempt, indicating recurring but unsuccessful legislative interest in comprehensive privacy regulation.

Material ScopeRed

No statute defines 'personal data' or comprehensive processing scope; MCPA scope is limited to unfair/deceptive trade practices, and the breach statute's scope is limited to specific PII categories triggering notification.

Absence provenance: not recorded. Searched: Mississippi comprehensive privacy law material scope, Mississippi Code personal data definition.

Territorial ScopeRed

No state-specific extraterritorial trigger exists; FTC Act jurisdiction rests on the federal interstate-commerce nexus rather than a Mississippi-specific long-arm privacy provision.

Absence provenance: not recorded. Searched: Mississippi privacy law extraterritorial application.

Regulator Registration And FilingRed

There is no controller/processor registration or filing regime with the Mississippi AG comparable to EU DPA registration models.

Absence provenance: not recorded. Searched: Mississippi data controller registration requirement.

Category narrative84 words

Mississippi has no comprehensive, GDPR/CCPA-style consumer-privacy statute. The operative legal architecture is (a) the federal FTC Act Section 5 general unfair/deceptive-practices authority, applicable nationally including Mississippi; (b) the state's own general consumer-protection statute, the Mississippi Consumer Protection Act (Miss. Code Ann. § 75-24-1 et seq.), enforced by the Mississippi Attorney General; and (c) a state data-breach notification statute addressing breach notice only, not broader access/deletion/portability rights. Two attempts to pass a comprehensive Mississippi consumer data privacy/protection act (2023 and 2025 sessions) died in committee.

Sources and claims (4)
  1. ConfirmedFederal Trade CommissionThe Federal Trade Commission Act Section 5 provides general unfair/deceptive-practices privacy enforcement authority applicable nationally, including in Mississippi.observed
  2. ConfirmedCalifornia Attorney General (multistate filing)Mississippi has enacted its own general consumer-protection statute, the Mississippi Consumer Protection Act, Miss. Code Ann. §75-24-1 et seq., which the Mississippi Attorney General enforces for unfair or deceptive trade practices.observed
  3. ConfirmedDataGuidanceMississippi has no enacted comprehensive consumer-privacy statute; a 2025 Senate bill for a Mississippi Consumer Data Privacy Act died without passage, following a similar failed 2023 attempt.observed
  4. ProbableDataGuidanceA separate Mississippi Consumer Data Protection Act bill was referred to committee in the 2025 session as a distinct legislative attempt, indicating recurring but unsuccessful legislative interest in comprehensive privacy regulation.observed

#

No comprehensive lawful-basis, consent, special-category, or anonymisation regime exists under Mississippi state law.

Traffic-light rationale — RedNo comprehensive lawful-basis, consent, special-category, or anonymisation regime exists under Mississippi state law.

Sub-modules (4)

Lawful BasesRed

No enumerated lawful bases exist under Mississippi law.

Absence provenance: not recorded. Searched: Mississippi lawful basis processing personal data statute.

Claims (1):

  • Mississippi has not enacted a comprehensive consumer-privacy statute and therefore has no codified lawful-basis, consent, or special-category framework analogous to GDPR Articles 6, 7, and 9.

Special CategoriesRed

No sensitive/special-category data regime exists under state law.

Absence provenance: not recorded. Searched: Mississippi sensitive personal data biometric health statute.

Pseudonymisation And AnonymisationRed

No statutory pseudonymisation/anonymisation definitions or safe harbours exist.

Absence provenance: not recorded. Searched: Mississipi anonymisation pseudonymisation safe harbor statute.

Category narrative56 words

Mississippi has no statutory lawful-basis framework, no defined consent-threshold standard, no special/sensitive-category regime, and no pseudonymisation/anonymisation safe-harbour comparable to GDPR Art 6/7/9 or state omnibus analogues. This module is a genuine regulatory gap at the state level; federal sectoral consent rules (e.g., COPPA parental consent, GLBA opt-out) are tracked separately under sectoral_watch/children_and_vulnerable_groups rather than duplicated here.

Sources and claims (1)
  1. ConfirmedDataGuidanceMississippi has not enacted a comprehensive consumer-privacy statute and therefore has no codified lawful-basis, consent, or special-category framework analogous to GDPR Articles 6, 7, and 9.observed

#

No state-level DSAR framework, deadlines, or portability right exists.

Traffic-light rationale — RedNo state-level DSAR framework, deadlines, or portability right exists.

Sub-modules (5)

Access RightRed

No general state-law access right exists outside sector-specific federal law.

Absence provenance: not recorded. Searched: Mississippi consumer right to access personal data statute.

Claims (1):

  • Mississippi does not confer a general consumer right of access, correction, deletion, restriction, objection, or portability over personal data by statute; such rights exist in the state only through incidental application of federal sectoral law.

Rectification And ErasureRed

No general correction or deletion right exists under state law.

Absence provenance: not recorded. Searched: Mississippi right to delete personal data statute.

Restriction And ObjectionRed

No restriction-of-processing or objection/profiling opt-out right exists under state law.

Absence provenance: not recorded. Searched: Mississippi right to object profiling opt out statute.

Data PortabilityRed

No portability right exists under state law.

Absence provenance: not recorded. Searched: Mississippi data portability right statute.

Deadlines And Response WindowsRed

No statutory response-window applies to consumer data requests generally (breach-notice timing is tracked separately under controller_processor_duties.breach_notification).

Absence provenance: not recorded. Searched: Mississippi data subject request deadline statute.

Category narrative52 words

Mississippi grants no state-law rights of access, rectification, erasure, restriction, objection, or portability to consumers over their personal data. Such rights only arise incidentally where a federal sectoral statute applies (e.g., HIPAA access right for protected health information, FCRA dispute rights for credit file data) — tracked under sectoral_watch, not duplicated here.

Sources and claims (1)
  1. ConfirmedDataGuidanceMississippi does not confer a general consumer right of access, correction, deletion, restriction, objection, or portability over personal data by statute; such rights exist in the state only through incidental application of federal sectoral law.observed

#

Breach notification is a live, in-force obligation (amber-worthy positive finding), but accountability/DPIA/DPO/ROPA/retention sub-modules are genuine gaps (red).

Primary frameworkMississippi data-breach notification statute
Supervisory authorityMississippi Attorney General
Traffic-light rationale — AmberBreach notification is a live, in-force obligation (amber-worthy positive finding), but accountability/DPIA/DPO/ROPA/retention sub-modules are genuine gaps (red).

Sub-modules (7)

Accountability And DpiaRed

No state-law accountability principle or DPIA trigger exists.

Absence provenance: not recorded. Searched: Mississippi data protection impact assessment requirement.

Dpo RequirementsRed

No DPO appointment threshold exists under state law.

Absence provenance: not recorded. Searched: Mississippi data protection officer requirement statute.

Ropa RequirementsRed

No records-of-processing obligation exists under state law.

Absence provenance: not recorded. Searched: Mississippi records of processing activities requirement.

Joint Controller ArrangementsRed

No joint-controller regime exists under state law.

Absence provenance: not recorded. Searched: Mississippi joint controller data processing agreement statute.

Security MeasuresRed

No general technical/organisational security-of-processing mandate exists outside the breach-notice context and sector-specific federal rules.

Absence provenance: not recorded. Searched: Mississippi data security requirements statute general.

Breach NotificationAmber

Mississippi's data-breach notification statute requires notice to affected residents following discovery of a security breach; the Attorney General's office has publicly urged prompt notification to her office as well.

Claims (2):

  • Mississippi has a data-breach notification law that requires breached entities to notify Mississippi residents who may be affected by a breach of security.
  • The Mississippi Attorney General's office has indicated it is best practice for breached entities to notify the AG's office quickly following a security breach, and a company with an existing security breach policy may satisfy Mississippi's breach requirements automatically.

Retention And DisposalRed

No general retention-limit or disposal-duty statute exists under Mississippi law outside sector-specific federal rules.

Absence provenance: not recorded. Searched: Mississippi data retention disposal requirement statute.

Category narrative73 words

The only genuinely Mississippi-specific controller duty of note is the state's breach-notification statute, which requires notice to affected Mississippi residents following discovery of a security breach; the state's Attorney General has publicly encouraged prompt notification to her office. There is no state-law DPIA trigger, DPO threshold, ROPA requirement, joint-controller regime, or general security-of-processing mandate outside the breach context and sector-specific federal law (HIPAA Security Rule, GLBA Safeguards Rule), which are tracked under sectoral_watch.

Sources and claims (2)
  1. ConfirmedNAAGMississippi has a data-breach notification law that requires breached entities to notify Mississippi residents who may be affected by a breach of security.observed
  2. ProbableIAPPThe Mississippi Attorney General's office has indicated it is best practice for breached entities to notify the AG's office quickly following a security breach, and a company with an existing security breach policy may satisfy Mississippi's breach requirements automatically.observed

#

No state-level transfer mechanism, adequacy determination, or localisation rule exists; this is a structural gap common to all non-omnibus U.S. states.

Traffic-light rationale — RedNo state-level transfer mechanism, adequacy determination, or localisation rule exists; this is a structural gap common to all non-omnibus U.S. states.

Sub-modules (6)

Transfer MechanismsRed

No Mississippi-specific transfer mechanism exists.

Absence provenance: not recorded. Searched: Mississippi cross border data transfer law.

Claims (1):

  • Mississippi has not enacted any state-specific cross-border data transfer mechanism, adequacy framework, or data-localisation requirement; this domain is governed entirely by counterpart jurisdictions' own transfer rules and by whatever federal sectoral law applies, none of which is Mississippi-specific.

Adequacy ReceivedRed

Not applicable; the US has no federal or state adequacy-receiving mechanism analogous to GDPR Art 45.

Absence provenance: not recorded. Searched: Mississippi adequacy decision received.

Adequacy GrantedRed

Mississippi does not grant adequacy decisions; this is not a state-level competence.

Absence provenance: not recorded. Searched: Mississippi adequacy decision granted other jurisdictions.

Sccs And BcrsRed

No state-level SCC/BCR uptake requirement or form exists.

Absence provenance: not recorded. Searched: Mississippi standard contractual clauses binding corporate rules.

Transfer Impact AssessmentRed

No TIA requirement exists under Mississippi law.

Absence provenance: not recorded. Searched: Mississippi transfer impact assessment requirement.

Data LocalisationRed

No data-localisation mandate exists under Mississippi law.

Absence provenance: not recorded. Searched: Mississippi data localisation requirement statute.

Category narrative59 words

Mississippi has no state-specific cross-border transfer mechanism, adequacy regime, SCC/BCR framework, transfer-impact-assessment requirement, or data-localisation mandate. Cross-border data flows touching Mississippi residents are governed exclusively by whatever federal sectoral or general U.S. rules apply (none of which are Mississippi-specific), and by counterpart jurisdictions' own outbound-transfer rules (e.g., GDPR Art 44-49 governing EU-to-US flows) rather than by any Mississippi instrument.

Sources and claims (1)
  1. ProbableDataGuidanceMississippi has not enacted any state-specific cross-border data transfer mechanism, adequacy framework, or data-localisation requirement; this domain is governed entirely by counterpart jurisdictions' own transfer rules and by whatever federal sectoral law applies, none of which is Mississippi-specific.observed

#

Federal sectoral overlays (HIPAA/GLBA/COPPA) are well-established and apply in full force; state-level sectoral overlays beyond breach law and the contested Social Media Safety Act are largely absent or unconfirmed.

Primary frameworkHIPAA (health) / GLBA (financial) / COPPA (children) — federal sectoral overlays; Mississippi Social Media Safety Act (state, contested)
Traffic-light rationale — AmberFederal sectoral overlays (HIPAA/GLBA/COPPA) are well-established and apply in full force; state-level sectoral overlays beyond breach law and the contested Social Media Safety Act are largely absent or unconfirmed.

Sub-modules (7)

Financial Sector OverlayGreen

GLBA imposes an affirmative and continuing obligation on financial institutions operating in Mississippi to protect customer non-public personal information, including privacy-notice and Safeguards Rule security duties; Mississippi has not enacted a stricter state financial-privacy overlay.

Claims (1):

  • The Gramm-Leach-Bliley Act imposes an affirmative and continuing obligation on financial institutions to respect customer privacy and protect the security and confidentiality of non-public personal information, and this obligation applies to financial institutions operating in Mississippi absent a stricter state overlay.

Health Sector OverlayGreen

HIPAA applies fully to Mississippi covered entities and is non-preemptive of stricter state medical-privacy law; Mississippi has not enacted a medical-privacy law stricter than HIPAA.

Claims (1):

  • HIPAA does not preempt state privacy laws for covered entities, and where both state and federal requirements exist the stricter privacy protection applies; Mississippi has not enacted medical-privacy protections stricter than HIPAA.

Telecoms And EprivacyRed

No Mississippi-specific ePrivacy/cookie-consent overlay exists; only general FTC Act coverage of deceptive tracking practices applies.

Absence provenance: not recorded. Searched: Mississippi ePrivacy telecoms cookie law.

Employment DataRed

No Mississippi-specific employment-data privacy statute exists.

Absence provenance: not recorded. Searched: Mississippi employee data privacy statute.

Credit And ScoringAmber

Credit data is regulated federally via FCRA; Mississippi has no state-specific credit-scoring privacy overlay.

Absence provenance: not recorded. Searched: Mississippi credit scoring privacy statute.

EducationAmber

Education data is regulated federally via FERPA; no Mississippi-specific student-data privacy overlay was confirmed in this run.

Absence provenance: not recorded. Searched: Mississippi student data privacy law FERPA overlay.

InsuranceAmber

Mississippi's adoption of the NAIC Insurance Data Security Model Law (2017) could not be confirmed in this run; Mississippi is listed among states referencing the older 1992 NAIC Insurance Information and Privacy Protection Model Act, but that is a distinct, earlier instrument.

Absence provenance: not recorded. Searched: Mississippi Insurance Data Security Law NAIC model act, Mississippi NAIC model law adoption 2026.

Claims (1):

  • Mississippi is referenced among states with insurance-sector privacy provisions tied to the 1992 NAIC Insurance Information and Privacy Protection Model Act, but confirmation that Mississippi has separately adopted the 2017 NAIC Insurance Data Security Model Law could not be obtained in this research pass.
Category narrative135 words

Federal sectoral overlays apply fully in Mississippi in the absence of a state omnibus law: HIPAA (health data, non-preemptive of stricter state law, though Mississippi has none stricter in this space), GLBA (financial institution data, with the GLBA Safeguards Rule and privacy-notice obligations), and COPPA (children's online data, parental consent). Mississippi has separately enacted the Mississippi Social Media Safety Act, an age-verification statute for minors on social media, currently the subject of ongoing First Amendment litigation (NetChoice v. Fitch) rather than a data-protection statute per se — it is cross-referenced here and detailed under children_and_vulnerable_groups. Mississippi's adoption status of the NAIC Insurance Data Security Model Law (as distinct from the older 1992 NAIC Insurance Information and Privacy Protection Model Act, which Mississippi appears to reference) could not be confirmed and is flagged as a gap.

Sources and claims (3)
  1. ConfirmedIAPPThe Gramm-Leach-Bliley Act imposes an affirmative and continuing obligation on financial institutions to respect customer privacy and protect the security and confidentiality of non-public personal information, and this obligation applies to financial institutions operating in Mississippi absent a stricter state overlay.observed
  2. ConfirmedIAPPHIPAA does not preempt state privacy laws for covered entities, and where both state and federal requirements exist the stricter privacy protection applies; Mississippi has not enacted medical-privacy protections stricter than HIPAA.observed
  3. UncertainDataGuidanceMississippi is referenced among states with insurance-sector privacy provisions tied to the 1992 NAIC Insurance Information and Privacy Protection Model Act, but confirmation that Mississippi has separately adopted the 2017 NAIC Insurance Data Security Model Law could not be obtained in this research pass.observed

#

No adtech-specific statute exists at the state level; only general UDAP coverage applies.

Traffic-light rationale — RedNo adtech-specific statute exists at the state level; only general UDAP coverage applies.

Sub-modules (6)

Cookies And TrackersRed

No cookie/tracker consent statute exists.

Absence provenance: not recorded. Searched: Mississippi cookie consent law.

Claims (1):

  • Mississippi has no comprehensive privacy statute and consequently no cookie/tracker consent, dark-pattern, opt-out-signal, clean-room, cross-context-advertising, or direct-marketing-specific privacy regime; adtech practices are reachable only via general federal and state unfair/deceptive-practices authority.

Dark PatternsRed

No dark-pattern-specific prohibition exists beyond general UDAP coverage.

Absence provenance: not recorded. Searched: Mississippi dark patterns law.

Opt Out SignalsRed

No Global Privacy Control or DAA-style opt-out-signal recognition mandate exists.

Absence provenance: not recorded. Searched: Mississippi Global Privacy Control opt out signal law.

Clean Rooms And DcrRed

No clean-room/data-collaboration-room regulation exists.

Absence provenance: not recorded. Searched: Mississippi data clean room regulation.

Cross Context AdvertisingRed

No 'sale'/'share' or cross-context-advertising framework exists.

Absence provenance: not recorded. Searched: Mississippi cross context behavioral advertising sale opt out law.

Direct MarketingRed

No direct-marketing-specific consent/suppression statute exists beyond general federal telemarketing/CAN-SPAM coverage.

Absence provenance: not recorded. Searched: Mississippi direct marketing consent suppression law.

Category narrative50 words

Mississippi has no state-specific cookie/tracker consent law, dark-pattern prohibition, opt-out-signal (e.g., GPC) recognition requirement, clean-room regulation, or 'sale'/'share' cross-context-advertising framework analogous to CPRA. Deceptive adtech practices remain reachable only via the general FTC Act Section 5 and the Mississippi Consumer Protection Act's unfair/deceptive-practices standard, not via any privacy-specific adtech statute.

Sources and claims (1)
  1. ConfirmedDataGuidanceMississippi has no comprehensive privacy statute and consequently no cookie/tracker consent, dark-pattern, opt-out-signal, clean-room, cross-context-advertising, or direct-marketing-specific privacy regime; adtech practices are reachable only via general federal and state unfair/deceptive-practices authority.observed

#

No state-level ADM transparency, AI risk-assessment, biometric, or genetic-data regime exists; this module is a genuine gap.

Traffic-light rationale — RedNo state-level ADM transparency, AI risk-assessment, biometric, or genetic-data regime exists; this module is a genuine gap.

Sub-modules (6)

Profiling RestrictionsRed

No profiling-restriction statute exists.

Absence provenance: not recorded. Searched: Mississippi automated profiling restriction law.

Claims (1):

  • Mississippi has not enacted profiling-restriction, ADM-transparency, or AI-specific risk-assessment legislation comparable to GDPR Article 22 or state omnibus analogues such as Colorado's algorithmic-discrimination law.

Automated Decision Making TransparencyRed

No ADM transparency or explanation-right statute exists.

Absence provenance: not recorded. Searched: Mississippi automated decision making transparency law.

Ai Risk AssessmentsRed

No AI-specific risk-assessment statute exists.

Absence provenance: not recorded. Searched: Mississippi AI risk assessment law 2026.

Biometric RegimeRed

Mississippi is not among the states with a freestanding biometric-privacy law (Illinois, Texas, Washington remain the principal examples).

Claims (1):

  • Mississippi is not among the small set of U.S. states (Illinois, Texas, Washington) with freestanding biometric-privacy statutes.

Genetic DataRed

No genetic-data-specific statute exists under Mississippi law.

Absence provenance: not recorded. Searched: Mississippi genetic data privacy law.

State Surveillance CarveoutsRed

State-surveillance/national-security exemptions are governed by federal law and are not a Mississippi-specific competence.

Absence provenance: not recorded. Searched: Mississippi state surveillance national security carve out privacy law.

Category narrative85 words

Mississippi has no Article 22-style profiling restriction, ADM transparency/explanation right, AI-specific risk-assessment statute, freestanding biometric-privacy law, or genetic-data-specific statute. Illinois, Texas, and Washington remain the principal U.S. states with freestanding biometric privacy laws; Mississippi is not among them. The Mississippi Social Media Safety Act touches age-verification infrastructure (and thus indirectly biometric/identity-verification questions raised in the NetChoice v. Fitch litigation) but is a child-safety statute, not an ADM/biometric-governance statute, and is analysed under children_and_vulnerable_groups. State-surveillance carve-outs (national-security exemptions) are a matter of federal, not Mississippi, law.

Sources and claims (2)
  1. ProbableDataGuidanceMississippi has not enacted profiling-restriction, ADM-transparency, or AI-specific risk-assessment legislation comparable to GDPR Article 22 or state omnibus analogues such as Colorado's algorithmic-discrimination law.observed
  2. ProbableIAPPMississippi is not among the small set of U.S. states (Illinois, Texas, Washington) with freestanding biometric-privacy statutes.observed

#

A live, contested state statute exists (age_verification) with active federal appellate litigation and no final resolution, plus federal COPPA coverage; other sub-modules (parental_consent beyond COPPA, minor_profiling_bans, education_settings, dependent_adults) are gaps.

Primary frameworkMississippi Social Media Safety Act (contested, sub judice); COPPA (federal, in force)
Traffic-light rationale — AmberA live, contested state statute exists (age_verification) with active federal appellate litigation and no final resolution, plus federal COPPA coverage; other sub-modules (parental_consent beyond COPPA, minor_profiling_bans, education_settings, dependent_adults) are gaps.

Sub-modules (5)

Age VerificationAmber

The Mississippi Social Media Safety Act's age-verification mandate is enjoined pending the Fifth Circuit's second review in NetChoice v. Fitch; oral argument occurred in early February 2026 with judges signaling the statute may survive scrutiny, but no final ruling has issued.

Claims (3):

  • The Mississippi Social Media Safety Act requires covered social-media platforms to verify users' ages and implement measures designed to reduce minors' exposure to harmful online interactions.
  • NetChoice's second challenge to the Mississippi Social Media Safety Act returned to the U.S. Court of Appeals for the Fifth Circuit after Mississippi appealed a federal district court's injunction against enforcement, with oral argument held in early February 2026.
  • The Fifth Circuit and other federal courts have appeared inclined to hold Mississippi's and other states' age-verification requirements constitutional, though a Justice Kavanaugh concurrence in an earlier stage of related litigation suggested NetChoice had shown a likelihood of success on the merits of a First Amendment challenge.

Minor Profiling BansRed

No Mississippi-specific minor-profiling ban exists outside the Social Media Safety Act's harm-reduction measures.

Absence provenance: not recorded. Searched: Mississippi minor profiling ban statute.

Education SettingsRed

No Mississippi-specific student-data-protection statute was confirmed in this run beyond federal FERPA.

Absence provenance: not recorded. Searched: Mississippi student data privacy law education.

Dependent AdultsRed

No Mississippi-specific dependent-adults data-protection statute was identified.

Absence provenance: not recorded. Searched: Mississippi dependent adults elderly data protection law.

Category narrative114 words

Mississippi enacted the Mississippi Social Media Safety Act, which requires covered social-media platforms to verify users' ages and implement measures to reduce minors' exposure to harmful online interactions. NetChoice has challenged the law twice; a federal district court enjoined enforcement, Mississippi appealed, and the Fifth Circuit heard oral argument for a second time in early February 2026 in NetChoice v. Fitch, with the panel appearing inclined toward upholding the statute against the First Amendment/anonymity challenge, though no final appellate ruling has issued as of this run. Separately, COPPA's federal parental-consent regime for under-13 online data collection applies fully in Mississippi. There is no Mississippi-specific age-appropriate-design-code, minor-profiling ban, education-settings privacy statute, or dependent-adults data-protection statute.

Sources and claims (4)
  1. ConfirmedIAPPThe Mississippi Social Media Safety Act requires covered social-media platforms to verify users' ages and implement measures designed to reduce minors' exposure to harmful online interactions.observed
  2. ConfirmedIAPPNetChoice's second challenge to the Mississippi Social Media Safety Act returned to the U.S. Court of Appeals for the Fifth Circuit after Mississippi appealed a federal district court's injunction against enforcement, with oral argument held in early February 2026.observed
  3. ProbableFTC (workshop materials)The Fifth Circuit and other federal courts have appeared inclined to hold Mississippi's and other states' age-verification requirements constitutional, though a Justice Kavanaugh concurrence in an earlier stage of related litigation suggested NetChoice had shown a likelihood of success on the merits of a First Amendment challenge.observed
  4. ConfirmedFederal Trade CommissionThe Children's Online Privacy Protection Act requires website operators and apps to provide notice of data-collection activities and obtain verifiable parental consent before collecting personal information from children under 13, and this federal requirement applies fully within Mississippi.observed

#

Enforcement infrastructure (AG + FTC) is real and active, with a significant live appellate matter, but a comprehensive privacy-enforcement regime, private right of action, and collective-redress specifics remain unconfirmed or absent.

Primary frameworkMississippi Consumer Protection Act + FTC Act Section 5
Supervisory authorityMississippi Attorney General
Traffic-light rationale — AmberEnforcement infrastructure (AG + FTC) is real and active, with a significant live appellate matter, but a comprehensive privacy-enforcement regime, private right of action, and collective-redress specifics remain unconfirmed or absent.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

The Mississippi Attorney General may seek injunctions and civil penalties (e.g., up to $10,000 per violation in past MCPA litigation) for unfair/deceptive practices; the FTC has parallel Section 5 authority with over 80 federal consumer-protection statutes within its remit.

Claims (2):

  • The Mississippi Attorney General has sought civil penalties of up to $10,000 per violation under the Mississippi Consumer Protection Act in prior litigation, illustrating the statute's available remedies for unfair or deceptive practices.
  • The FTC has enforcement or administrative responsibilities under more than 80 federal consumer-protection laws, providing a broad concurrent federal enforcement layer applicable in Mississippi alongside state AG authority.

Enforcement Activity IndexAmber

The most visible recent Mississippi-specific enforcement/litigation activity is the state's defense of the Social Media Safety Act in NetChoice v. Fitch; no major MS-specific privacy fine or settlement was identified in this run.

Absence provenance: not recorded. Searched: Mississippi Attorney General privacy enforcement fine settlement 2026.

Claims (1):

  • Mississippi's most prominent recent privacy-adjacent enforcement activity is its defense of the Social Media Safety Act against NetChoice's constitutional challenge, rather than a traditional data-protection enforcement action.

Regulator Funding And CapacityRed

No specific funding/headcount data for a dedicated Mississippi privacy unit was identified; the AG's office operates as a general consumer-protection division.

Absence provenance: not recorded. Searched: Mississippi Attorney General consumer protection division funding headcount.

Collective Redress And Class ActionsRed

No dedicated collective-redress mechanism specific to privacy claims was identified beyond ordinary Mississippi class-action procedure.

Absence provenance: not recorded. Searched: Mississippi class action privacy data breach mechanism.

Private Right Of ActionAmber

Mississippi's specific position on a private right of action under its breach-notification statute could not be confirmed in this run; some U.S. state breach statutes permit private rights of action, but MS's status is unresolved.

Absence provenance: not recorded. Searched: Mississippi data breach statute private right of action.

Recent Developments 180DAmber

Within the last 180 days, the principal Mississippi-relevant data-protection development is the Fifth Circuit's early-February-2026 oral argument in NetChoice v. Fitch on the Social Media Safety Act's age-verification mandate.

Claims (1):

  • The Fifth Circuit heard oral arguments for the second time in NetChoice v. Fitch in early February 2026, concerning Mississippi's child social-media age-verification law, with the case's procedural history described as increasingly complicated.
Category narrative132 words

Enforcement in Mississippi runs through two parallel tracks: (1) the Mississippi Attorney General's authority under the Mississippi Consumer Protection Act, which permits injunctive relief and civil penalties for unfair/deceptive practices (illustrated by the AG's talc-labeling litigation against Johnson & Johnson) and separate breach-notification enforcement; and (2) FTC Section 5 federal enforcement, which the FTC increasingly coordinates with state AGs. The most significant recent development within the 180-day window is the continuing NetChoice v. Fitch litigation over the Social Media Safety Act, with Fifth Circuit oral argument in early February 2026. No Mississippi-specific private right of action for general data-privacy violations exists; breach-notification statutes in some U.S. states permit private rights of action but Mississippi's specific position was not confirmed in this run. No dedicated collective-redress mechanism beyond ordinary class-action procedure was identified.

Sources and claims (4)
  1. ConfirmedCalifornia Attorney General (multistate filing)The Mississippi Attorney General has sought civil penalties of up to $10,000 per violation under the Mississippi Consumer Protection Act in prior litigation, illustrating the statute's available remedies for unfair or deceptive practices.observed
  2. ConfirmedFederal Trade CommissionThe FTC has enforcement or administrative responsibilities under more than 80 federal consumer-protection laws, providing a broad concurrent federal enforcement layer applicable in Mississippi alongside state AG authority.observed
  3. ProbableIAPPMississippi's most prominent recent privacy-adjacent enforcement activity is its defense of the Social Media Safety Act against NetChoice's constitutional challenge, rather than a traditional data-protection enforcement action.observed
  4. ConfirmedIAPPThe Fifth Circuit heard oral arguments for the second time in NetChoice v. Fitch in early February 2026, concerning Mississippi's child social-media age-verification law, with the case's procedural history described as increasingly complicated.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for United States – Mississippi
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-06. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 23 claim(s), 15 source(s) in the cumulative register.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrectification and erasure
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressregulator powers and penalties
Art. 78Enforcement & Redressregulator powers and penalties
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 81Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redressprivate right of action
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

regulator_and_framework and enforcement_and_redress rest on a T1 anchor (FTC Act Section 5, ftc.gov) plus T2/T4 statute citations (NAAG, multistate court filing citing Miss. Code Ann. §75-24-1 et seq.) for the Mississippi Consumer Protection Act and breach-notification law. controller_processor_duties.breach_notification and children_and_vulnerable_groups.age_verification/parental_consent rest on T2/T3 sources (NAAG, IAPP) with one T1 anchor for COPPA. sectoral_watch rests on T3 IAPP analysis for HIPAA/GLBA non-preemption and a T1 FTC anchor for COPPA/privacy-security guidance; the insurance sub-module rests on unconfirmed T3/T4 sourcing and is flagged Uncertain. lawful_processing_and_special_data, data_subject_rights, cross_border_and_adequacy, adtech_and_commercial_privacy, and algorithmic_biometric_and_surveillance_governance are emitted as explicit gap findings (red, absent_field_provenance) because no comprehensive Mississippi statute exists to populate them, consistent with the injected seed's disambiguation note.

Unresolved questions (5):

  • What is the precise Mississippi Code section number for the state's data-breach notification statute (not confirmed via retrievable primary text in this run)?
  • Has Mississippi formally adopted the 2017 NAIC Insurance Data Security Model Law, as distinct from the older 1992 NAIC Insurance Information and Privacy Protection Model Act referenced in secondary sources?
  • What is the final disposition of the Fifth Circuit's second review in NetChoice v. Fitch (oral argument held early February 2026; no ruling identified as of this run)?
  • Does Mississippi's breach-notification statute include a private right of action, consistent with a minority of U.S. state breach laws?
  • Is there a Mississippi-specific student-data-privacy statute beyond federal FERPA that was not surfaced in this research pass?

Escalate to primary-source review: yes