🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
US-MO · run data-protection-2026-08-06 v13-gdpri-1.0.0
content: ai_generated 12 sources retrieved model claude-sonnet-5 ·

United States – Missouri

US-MO schema gdpri-v2 trajectory: not recordedregulated (sectoral)overlaps: FIM, WPM, AIC

Last updated · 10 categories · 53 claims · 12 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
53Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

A narrow but real state statute (breach notification) and clear regulator identity exist, but there is no comprehensive material/territorial scope framework, hence amber rather than green.

Primary frameworkMo. Rev. Stat. §407.1500 (breach notification) + federal FTC Act Section 5 baseline; no state omnibus privacy statute
Supervisory authorityMissouri Attorney General
Traffic-light rationale — AmberA narrow but real state statute (breach notification) and clear regulator identity exist, but there is no comprehensive material/territorial scope framework, hence amber rather than green.

Sub-modules (5)

Regulator And AuthorityAmber

The Missouri Attorney General is the sole state authority with statutory enforcement power over §407.1500; there is no dedicated state data-protection authority analogous to a DPA.

Claims (1):

  • Missouri has no comprehensive consumer-privacy statute; the Missouri Attorney General enforces general consumer-protection law and the state breach-notification statute in this space.

Act And InstrumentsAmber

The principal instrument is Mo. Rev. Stat. §407.1500; there is no Missouri-equivalent of GDPR/CCPA.

Claims (2):

  • The primary state-level data-protection instrument in Missouri is the data-breach notification statute at Mo. Rev. Stat. §407.1500, Chapter 407, Title XXVI.
  • Federal Trade Commission Act Section 5 unfair-or-deceptive-practices authority applies nationally, including to Missouri entities, as a general privacy-and-security enforcement baseline in the absence of a state omnibus law.

Material ScopeRed

Material scope is narrow, tracking identity-theft/financial-fraud data elements typical of first-generation US breach laws rather than a broad 'personal data' definition.

Claims (1):

  • US state breach-notification statutes, including Missouri's, generally define covered personal information narrowly around identity-theft and financial-fraud data elements, in contrast to the broader definitions used in comprehensive state privacy laws.

Territorial ScopeAmber

The breach statute applies based on the residency of affected individuals (Missouri residents) and a 1,000-resident AG-notification threshold, rather than a controller-establishment test.

Claims (1):

  • Notification under Missouri's breach statute must be provided without undue delay to consumers and to the Missouri Attorney General where the breach involves the information of more than 1,000 Missouri residents.

Regulator Registration And FilingRed

No general controller registration or filing scheme exists; AG notice is triggered only by the breach threshold.

Claims (1):

  • Missouri imposes no general controller registration or filing regime; the only filing-adjacent duty is threshold-triggered breach notice to the Attorney General.
Category narrative85 words

Missouri has no comprehensive consumer-privacy statute. The operative state instrument is the data-breach notification law at Mo. Rev. Stat. §407.1500 (Chapter 407, Title XXVI), enforced exclusively by the Missouri Attorney General. Absent a state omnibus law, general privacy conduct in Missouri is governed by the federal FTC Act Section 5 unfair/deceptive-practices authority and applicable federal sectoral statutes (HIPAA, GLBA, COPPA). No controller registration or filing regime exists at the state level; the only filing-adjacent obligation is AG notification once a breach crosses a 1,000-resident threshold.

Sources and claims (6)
  1. ConfirmedOneTrust DataGuidanceMissouri has no comprehensive consumer-privacy statute; the Missouri Attorney General enforces general consumer-protection law and the state breach-notification statute in this space.observed
  2. ConfirmedOneTrust DataGuidanceThe primary state-level data-protection instrument in Missouri is the data-breach notification statute at Mo. Rev. Stat. §407.1500, Chapter 407, Title XXVI.observed
  3. ConfirmedFederal Trade CommissionFederal Trade Commission Act Section 5 unfair-or-deceptive-practices authority applies nationally, including to Missouri entities, as a general privacy-and-security enforcement baseline in the absence of a state omnibus law.observed
  4. ProbableIAPPUS state breach-notification statutes, including Missouri's, generally define covered personal information narrowly around identity-theft and financial-fraud data elements, in contrast to the broader definitions used in comprehensive state privacy laws.observed
  5. ConfirmedOneTrust DataGuidanceNotification under Missouri's breach statute must be provided without undue delay to consumers and to the Missouri Attorney General where the breach involves the information of more than 1,000 Missouri residents.observed
  6. ConfirmedOneTrust DataGuidanceMissouri imposes no general controller registration or filing regime; the only filing-adjacent duty is threshold-triggered breach notice to the Attorney General.observed

#

Only a single narrow biometric-consent carve-out exists; there is no general lawful-basis or special-category framework, consistent with the seed's disambiguation note.

Primary frameworkNo general lawful-basis statute; Missouri House Bill 1584 (biometric consent) is the sole special-category-adjacent rule
Supervisory authorityMissouri Attorney General
Traffic-light rationale — RedOnly a single narrow biometric-consent carve-out exists; there is no general lawful-basis or special-category framework, consistent with the seed's disambiguation note.

Sub-modules (4)

Lawful BasesRed

No GDPR Art 6-equivalent enumeration of lawful processing bases exists in Missouri law.

Claims (1):

  • Missouri has no statutory enumeration of lawful bases for processing personal data equivalent to GDPR Article 6.

Special CategoriesAmber

Biometric identifiers are the only category subject to a dedicated consent/policy regime, under HB 1584.

Claims (1):

  • Missouri House Bill 1584, effective 28 August 2024, requires private entities to obtain consent and maintain public policies before collecting biometric identifiers, functioning as Missouri's only sensitive-category-specific consent rule.

Pseudonymisation And AnonymisationAmber

No state-law definition exists; the closest analogue is the federal FERPA de-identification safe harbor (34 CFR §99.31(b)) applicable to Missouri schools receiving federal education funds.

Claims (1):

  • The federal FERPA de-identification safe harbor permits schools to release education records without consent once personally identifiable information has been removed and re-identification risk reasonably assessed, applicable to Missouri educational agencies receiving federal funds.
Category narrative49 words

Missouri has no statutory enumeration of lawful processing bases, no general consent standard, and no special/sensitive-category regime, with the narrow exception of House Bill 1584's biometric-data consent requirement (effective 28 August 2024). Pseudonymisation/anonymisation is addressed only indirectly, via the federal FERPA de-identification safe harbor applicable to Missouri educational agencies.

Sources and claims (4)
  1. ProbableOneTrust DataGuidanceMissouri House Bill 1584, effective 28 August 2024, requires private entities to obtain consent and maintain public policies before collecting biometric identifiers, functioning as Missouri's only sensitive-category-specific consent rule.observed
  2. ConfirmedOneTrust DataGuidanceOutside the HB 1584 biometric-consent requirement, Missouri imposes no general consent standard for the processing of personal data.observed
  3. ConfirmedOneTrust DataGuidanceMissouri has no statutory enumeration of lawful bases for processing personal data equivalent to GDPR Article 6.observed
  4. ConfirmedIAPPThe federal FERPA de-identification safe harbor permits schools to release education records without consent once personally identifiable information has been removed and re-identification risk reasonably assessed, applicable to Missouri educational agencies receiving federal funds.observed

#

No DSAR-equivalent rights exist in Missouri law; this is a genuine regulatory gap, not an omission of research.

Supervisory authorityMissouri Attorney General
Traffic-light rationale — RedNo DSAR-equivalent rights exist in Missouri law; this is a genuine regulatory gap, not an omission of research.

Sub-modules (5)

Access RightRed

No statutory right of access to personal data exists in Missouri.

Claims (1):

  • Missouri law confers no general consumer right of access to personal data held by a business.

Rectification And ErasureRed

No statutory right to correct or delete personal data exists in Missouri.

Claims (1):

  • Missouri law confers no general consumer right to rectify or erase personal data held by a business.

Restriction And ObjectionRed

No statutory right to restrict processing or object (including to profiling) exists in Missouri.

Claims (1):

  • Missouri law confers no general consumer right to restrict processing or object to processing, including profiling.

Data PortabilityRed

No statutory portability right exists in Missouri.

Claims (1):

  • Missouri law confers no general consumer data-portability right.

Deadlines And Response WindowsAmber

The only statutory timing obligation is breach notice 'without undue delay'; no consumer rights-request deadline exists because no rights framework exists.

Claims (1):

  • Missouri's breach statute requires notification to consumers without undue delay, but no statutory deadline exists for responding to consumer data-rights requests because no such rights regime exists.
Category narrative49 words

Missouri confers no general access, rectification, erasure, restriction/objection, or portability rights on consumers with respect to personal data. The only consumer-facing entitlement is the statutory expectation of breach notice 'without undue delay' once a qualifying breach occurs; there is no rights-request response-time regime because no underlying rights framework exists.

Sources and claims (5)
  1. ConfirmedOneTrust DataGuidanceMissouri law confers no general consumer right of access to personal data held by a business.observed
  2. ConfirmedOneTrust DataGuidanceMissouri law confers no general consumer right to rectify or erase personal data held by a business.observed
  3. ConfirmedOneTrust DataGuidanceMissouri law confers no general consumer right to restrict processing or object to processing, including profiling.observed
  4. ConfirmedOneTrust DataGuidanceMissouri law confers no general consumer data-portability right.observed
  5. ConfirmedOneTrust DataGuidanceMissouri's breach statute requires notification to consumers without undue delay, but no statutory deadline exists for responding to consumer data-rights requests because no such rights regime exists.observed

#

Breach notification is a real, binding, in-force duty (amber-worthy baseline), but every other accountability duty is absent, preventing a green rating.

Primary frameworkMo. Rev. Stat. §407.1500 (breach notification only)
Supervisory authorityMissouri Attorney General
Traffic-light rationale — AmberBreach notification is a real, binding, in-force duty (amber-worthy baseline), but every other accountability duty is absent, preventing a green rating.

Sub-modules (7)

Accountability And DpiaRed

No DPIA or general accountability-principle statute exists in Missouri.

Claims (1):

  • Missouri has no statutory Data Protection Impact Assessment or general accountability-principle requirement.

Dpo RequirementsRed

No DPO appointment requirement exists in Missouri.

Claims (1):

  • Missouri has no statutory Data Protection Officer appointment threshold or requirement.

Ropa RequirementsRed

No records-of-processing requirement exists in Missouri.

Claims (1):

  • Missouri has no statutory records-of-processing-activities requirement.

Joint Controller ArrangementsRed

No statutory joint-controller framework exists in Missouri; any analogous duties arise only under federal sectoral law (e.g., GLBA/HIPAA service-provider provisions), which falls outside this state-level baseline.

Claims (1):

  • Missouri has no statutory joint-controller allocation-of-responsibility framework.

Security MeasuresAmber

No general statutory information-security-program mandate was confirmed at the state level; adoption of NAIC-model insurance-sector security standards in Missouri could not be verified in this pass.

Claims (1):

  • No general Missouri state-law mandate for technical/organisational security-of-processing measures was confirmed; potential sector-specific NAIC Insurance Data Security Model Law adoption in Missouri could not be verified in this research pass.

Breach NotificationGreen

Missouri's core, binding data-protection duty: notify affected consumers without undue delay and notify the Attorney General once the 1,000-resident threshold is met; notice may be written, electronic, or telephonic.

Claims (2):

  • Missouri law requires notification to affected consumers without undue delay, and to the Missouri Attorney General, when a breach affects the personal information of more than 1,000 Missouri residents.
  • Notification under Missouri's breach statute may be provided in writing, in electronic form, or by telephone.

Retention And DisposalRed

No general statutory retention-limitation or disposal duty exists in Missouri outside the narrow biometric-retention-policy element of HB 1584.

Claims (1):

  • Missouri has no general statutory data-retention-limitation or disposal duty outside the narrow biometric-policy element of HB 1584.
Category narrative60 words

The only substantive controller duty under Missouri state law is breach notification under §407.1500. There is no statutory DPIA, DPO, ROPA, joint-controller, general security-measures, or retention/disposal regime at the state level. Sector-specific security obligations (e.g., insurance data-security standards potentially modeled on the NAIC Insurance Data Security Model Law) could not be confirmed as adopted in Missouri within this research pass.

Sources and claims (8)
  1. ConfirmedOneTrust DataGuidanceMissouri law requires notification to affected consumers without undue delay, and to the Missouri Attorney General, when a breach affects the personal information of more than 1,000 Missouri residents.observed
  2. ConfirmedOneTrust DataGuidanceNotification under Missouri's breach statute may be provided in writing, in electronic form, or by telephone.observed
  3. UncertainIAPPNo general Missouri state-law mandate for technical/organisational security-of-processing measures was confirmed; potential sector-specific NAIC Insurance Data Security Model Law adoption in Missouri could not be verified in this research pass.observed
  4. ConfirmedOneTrust DataGuidanceMissouri has no statutory Data Protection Impact Assessment or general accountability-principle requirement.observed
  5. ConfirmedOneTrust DataGuidanceMissouri has no statutory Data Protection Officer appointment threshold or requirement.observed
  6. ConfirmedOneTrust DataGuidanceMissouri has no statutory records-of-processing-activities requirement.observed
  7. ConfirmedOneTrust DataGuidanceMissouri has no statutory joint-controller allocation-of-responsibility framework.observed
  8. ConfirmedOneTrust DataGuidanceMissouri has no general statutory data-retention-limitation or disposal duty outside the narrow biometric-policy element of HB 1584.observed

#

No state-level transfer, adequacy, or localisation regime exists; explicit absence per JID-adaptive rules for US state JIDs.

Traffic-light rationale — RedNo state-level transfer, adequacy, or localisation regime exists; explicit absence per JID-adaptive rules for US state JIDs.

Sub-modules (6)

Transfer MechanismsRed

No Missouri state-level transfer-mechanism regime exists; any applicable mechanisms (EU-US DPF, SCCs) operate at the federal/EU level, outside the US-MO JID.

Claims (1):

  • Missouri has no independent state-level cross-border personal-data transfer regime; applicable mechanisms operate at the federal/EU level.

Adequacy ReceivedRed

Adequacy determinations are a federal/EU-level matter; Missouri has no independent adequacy status.

Absence provenance: not recorded. Searched: M, i, s, s, o, u, r, i, , s, t, a, t, e, , a, d, e, q, u, a, c, y, , d, e, t, e, r, m, i, n, a, t, i, o, n, , E, U, , G, D, P, R.

Adequacy GrantedRed

Missouri does not independently grant adequacy status to other jurisdictions; this is a federal/EU-level construct.

Absence provenance: not recorded. Searched: M, i, s, s, o, u, r, i, , a, d, e, q, u, a, c, y, , d, e, c, i, s, i, o, n, s, , g, r, a, n, t, e, d, , t, o, , o, t, h, e, r, , j, u, r, i, s, d, i, c, t, i, o, n, s.

Sccs And BcrsRed

SCC/BCR uptake is a matter of federal/EU cross-border transfer law, not independently regulated by Missouri.

Absence provenance: not recorded. Searched: M, i, s, s, o, u, r, i, , S, C, C, , B, C, R, , s, t, a, t, e, , l, a, w, , r, e, q, u, i, r, e, m, e, n, t.

Transfer Impact AssessmentRed

No Missouri-specific transfer-impact-assessment requirement exists.

Absence provenance: not recorded. Searched: M, i, s, s, o, u, r, i, , t, r, a, n, s, f, e, r, , i, m, p, a, c, t, , a, s, s, e, s, s, m, e, n, t, , r, e, q, u, i, r, e, m, e, n, t.

Data LocalisationRed

Missouri imposes no state-level data-localisation mandate on personal-data processing.

Claims (1):

  • Missouri imposes no state-level data-localisation mandate requiring personal data to be stored or processed within the state.
Category narrative58 words

Missouri, as a US state, has no independent cross-border-transfer regime, no data-localisation mandate, and no state-level role in adequacy determinations. Cross-border transfer mechanisms (e.g., the EU-US Data Privacy Framework, SCCs) operate at the federal/EU level and are outside the scope of Missouri state law; this module is therefore a structural gap by design rather than a research omission.

Sources and claims (2)
  1. ConfirmedOneTrust DataGuidanceMissouri has no independent state-level cross-border personal-data transfer regime; applicable mechanisms operate at the federal/EU level.observed
  2. ConfirmedOneTrust DataGuidanceMissouri imposes no state-level data-localisation mandate requiring personal data to be stored or processed within the state.observed

#

Federal sectoral coverage is solid and confirmed; state-level sectoral detail (insurance, communications, credit cards) is thin and partly unverified.

Primary frameworkFederal sectoral statutes (GLBA, HIPAA, FERPA, COPPA, FCRA) overlaid on Missouri's narrow state provisions
Supervisory authorityMissouri Attorney General
Traffic-light rationale — AmberFederal sectoral coverage is solid and confirmed; state-level sectoral detail (insurance, communications, credit cards) is thin and partly unverified.

Sub-modules (7)

Financial Sector OverlayAmber

GLBA applies nationally to Missouri financial institutions, requiring privacy notices and safeguarding of non-public personal information.

Claims (1):

  • The federal Gramm-Leach-Bliley Act applies nationally to financial institutions operating in Missouri, imposing privacy-notice and safeguarding obligations for non-public personal information.

Health Sector OverlayAmber

HIPAA applies nationally to Missouri covered entities; DataGuidance also notes unspecified Missouri health-information rules.

Claims (1):

  • Missouri legislation includes additional rules touching health information alongside the federal HIPAA framework that applies to covered entities nationally.

Telecoms And EprivacyRed

DataGuidance references additional Missouri rules on communications, but the specific statute and scope could not be independently verified in this pass; no state cookie/ePrivacy-style law was identified.

Claims (1):

  • Missouri legislation reportedly includes additional rules on communications, though the specific statute and its scope relative to telecoms/eprivacy could not be independently verified in this research pass.

Employment DataRed

No comprehensive Missouri employment-data privacy statute was identified.

Claims (1):

  • No comprehensive Missouri employment-data privacy statute displacing or supplementing general federal employment-privacy law was identified.

Credit And ScoringAmber

The federal Fair Credit Reporting Act governs credit-related personal data nationally; DataGuidance references unspecified Missouri credit-card rules, not independently verified here.

Claims (1):

  • The federal Fair Credit Reporting Act governs credit-scoring and credit-reporting personal data nationally; Missouri legislation additionally references unspecified credit-card-related rules.

EducationAmber

FERPA and COPPA jointly govern Missouri's education/ed-tech sector at the federal level; no distinct Missouri student-data-privacy statute was identified in this research.

Claims (1):

  • FERPA and COPPA jointly govern personal-data handling in Missouri's education and ed-tech sectors at the federal level; no distinct Missouri student-data-privacy statute was identified in this research.

InsuranceRed

Whether Missouri has adopted the NAIC Insurance Data Security Model Law (adopted by NAIC in 2017 and enacted variously by other states) could not be confirmed in this research pass.

Claims (1):

  • Whether Missouri has enacted a version of the NAIC Insurance Data Security Model Law (as South Carolina, Ohio, and Michigan have) could not be confirmed in this research pass.
Category narrative70 words

Federal sectoral overlays supply the substantive privacy content Missouri's own statute book lacks: GLBA for financial institutions, HIPAA for covered health entities, FERPA/COPPA for education and children's data, and FCRA for credit reporting. Missouri's own legislation supplements this narrowly around communications, credit cards, and health information, per DataGuidance's jurisdiction overview, but the specifics of the state-level communications/credit-card rules and insurance-sector security standards could not be independently confirmed in this pass.

Sources and claims (7)
  1. ConfirmedFederal Trade CommissionThe federal Gramm-Leach-Bliley Act applies nationally to financial institutions operating in Missouri, imposing privacy-notice and safeguarding obligations for non-public personal information.observed
  2. ProbableOneTrust DataGuidanceMissouri legislation includes additional rules touching health information alongside the federal HIPAA framework that applies to covered entities nationally.observed
  3. UncertainOneTrust DataGuidanceMissouri legislation reportedly includes additional rules on communications, though the specific statute and its scope relative to telecoms/eprivacy could not be independently verified in this research pass.observed
  4. UncertainOneTrust DataGuidanceNo comprehensive Missouri employment-data privacy statute displacing or supplementing general federal employment-privacy law was identified.observed
  5. ProbableOneTrust DataGuidanceThe federal Fair Credit Reporting Act governs credit-scoring and credit-reporting personal data nationally; Missouri legislation additionally references unspecified credit-card-related rules.observed
  6. ConfirmedIAPPFERPA and COPPA jointly govern personal-data handling in Missouri's education and ed-tech sectors at the federal level; no distinct Missouri student-data-privacy statute was identified in this research.observed
  7. UncertainIAPPWhether Missouri has enacted a version of the NAIC Insurance Data Security Model Law (as South Carolina, Ohio, and Michigan have) could not be confirmed in this research pass.observed

#

This entire module is a structural gap in Missouri law, consistent with the seed's disambiguation note that Missouri lacks comprehensive consumer-privacy rights.

Traffic-light rationale — RedThis entire module is a structural gap in Missouri law, consistent with the seed's disambiguation note that Missouri lacks comprehensive consumer-privacy rights.

Sub-modules (6)

Cookies And TrackersRed

No Missouri cookie/tracker consent law exists.

Claims (1):

  • Missouri has no state-law cookie or tracker consent regime.

Dark PatternsRed

No Missouri dark-patterns prohibition statute exists.

Claims (1):

  • Missouri has no statute specifically prohibiting dark patterns in consumer-facing consent interfaces.

Opt Out SignalsRed

No Missouri statute requires recognition of universal opt-out signals such as Global Privacy Control.

Claims (1):

  • Missouri imposes no legal duty on businesses to recognize universal opt-out signals such as Global Privacy Control.

Clean Rooms And DcrRed

No Missouri clean-room/data-collaboration-room rules exist.

Claims (1):

  • Missouri has no statutory rules governing data clean rooms or data-collaboration arrangements.

Cross Context AdvertisingRed

No CPRA-style 'sale'/'share' cross-context-advertising regime exists in Missouri.

Claims (1):

  • Missouri has no CPRA-style statutory concept of 'sale' or 'share' of personal information triggering cross-context-advertising opt-out rights.

Direct MarketingAmber

Direct marketing in Missouri is governed only by generally applicable federal statutes (TCPA, CAN-SPAM); no Missouri-specific consent or suppression law was identified.

Claims (1):

  • Direct marketing to Missouri consumers is governed by generally applicable federal telemarketing and anti-spam statutes rather than a Missouri-specific consent or suppression law.
Category narrative49 words

Missouri has no cookie/tracker consent law, no dark-patterns prohibition, no Global-Privacy-Control-style opt-out-signal recognition duty, no clean-room/data-collaboration rules, and no CPRA-style 'sale'/'share' cross-context-advertising regime. Direct marketing is governed only by generally applicable federal telemarketing/anti-spam statutes (e.g., TCPA, CAN-SPAM), not by any Missouri-specific consent or suppression law identified in this research.

Sources and claims (6)
  1. ConfirmedOneTrust DataGuidanceMissouri has no state-law cookie or tracker consent regime.observed
  2. ConfirmedOneTrust DataGuidanceMissouri has no statute specifically prohibiting dark patterns in consumer-facing consent interfaces.observed
  3. ConfirmedOneTrust DataGuidanceMissouri imposes no legal duty on businesses to recognize universal opt-out signals such as Global Privacy Control.observed
  4. ConfirmedOneTrust DataGuidanceMissouri has no statutory rules governing data clean rooms or data-collaboration arrangements.observed
  5. ConfirmedIAPPMissouri has no CPRA-style statutory concept of 'sale' or 'share' of personal information triggering cross-context-advertising opt-out rights.observed
  6. ProbableFederal Trade CommissionDirect marketing to Missouri consumers is governed by generally applicable federal telemarketing and anti-spam statutes rather than a Missouri-specific consent or suppression law.observed

#

A real, in-force biometric regime exists (amber baseline), but profiling, ADM transparency, AI risk-assessment, and genetic-data sub-modules are all gaps.

Primary frameworkMissouri House Bill 1584 (biometric data consent/retention policy)
Supervisory authorityMissouri Attorney General
Traffic-light rationale — AmberA real, in-force biometric regime exists (amber baseline), but profiling, ADM transparency, AI risk-assessment, and genetic-data sub-modules are all gaps.

Sub-modules (6)

Profiling RestrictionsRed

No Missouri statute restricts profiling analogous to GDPR Article 22.

Claims (1):

  • Missouri has no statutory restriction on automated profiling analogous to GDPR Article 22.

Automated Decision Making TransparencyRed

No Missouri statute mandates ADM transparency or an explanation right for consumers.

Claims (1):

  • Missouri has no statute mandating automated-decision-making transparency or an explanation right for consumers.

Ai Risk AssessmentsRed

No comprehensive Missouri statute requires AI-specific risk assessments for personal-data processing; narrow AI bills identified (e.g., an AI Non-Sentience and Responsibility Act, an AI-in-political-advertising disclaimer bill) do not constitute a personal-data risk-assessment regime.

Claims (1):

  • No comprehensive Missouri statute mandates AI-specific risk assessments for personal-data processing; identified narrow AI-related bills (AI Non-Sentience and Responsibility Act; political-advertising AI-disclaimer bill) do not constitute a personal-data risk-assessment regime.

Biometric RegimeAmber

House Bill 1584, effective 28 August 2024, is Missouri's principal biometric-data regime, requiring consent and public retention/destruction policies from private entities collecting biometric identifiers.

Claims (1):

  • Missouri House Bill 1584, effective 28 August 2024, is the state's principal biometric-data regime, requiring private entities to adopt public retention/destruction policies and obtain consent prior to collecting biometric identifiers.

Genetic DataRed

No Missouri-specific genetic-data privacy statute was identified beyond potential federal GINA coverage of employment/insurance discrimination; this could not be fully verified in this pass.

Claims (1):

  • No Missouri-specific genetic-data privacy statute was identified in this research beyond potential federal GINA coverage of employment/insurance discrimination.

State Surveillance CarveoutsRed

No Missouri-specific state-surveillance carve-out affecting private-sector personal-data processing was identified in this research.

Claims (1):

  • No Missouri-specific state-surveillance carve-out affecting private-sector personal-data processing was identified; national-security/law-enforcement exemptions in this space are governed by federal frameworks outside the state consumer-privacy patchwork.
Category narrative65 words

Missouri's only concrete governance instrument in this module is House Bill 1584's biometric-data consent/retention-policy regime, effective 28 August 2024. There is no profiling-restriction or automated-decision-making transparency statute, no comprehensive AI-specific personal-data risk-assessment mandate, no identified genetic-data-specific statute, and no confirmed state-surveillance carve-out affecting private-sector processing. The Missouri Attorney General has opened investigatory activity into AI chatbots, which is enforcement-adjacent but not a binding transparency rule.

Sources and claims (6)
  1. ProbableOneTrust DataGuidanceMissouri House Bill 1584, effective 28 August 2024, is the state's principal biometric-data regime, requiring private entities to adopt public retention/destruction policies and obtain consent prior to collecting biometric identifiers.observed
  2. ConfirmedOneTrust DataGuidanceMissouri has no statutory restriction on automated profiling analogous to GDPR Article 22.observed
  3. ConfirmedOneTrust DataGuidanceMissouri has no statute mandating automated-decision-making transparency or an explanation right for consumers.observed
  4. UncertainOneTrust DataGuidanceNo comprehensive Missouri statute mandates AI-specific risk assessments for personal-data processing; identified narrow AI-related bills (AI Non-Sentience and Responsibility Act; political-advertising AI-disclaimer bill) do not constitute a personal-data risk-assessment regime.observed
  5. UncertainOneTrust DataGuidanceNo Missouri-specific genetic-data privacy statute was identified in this research beyond potential federal GINA coverage of employment/insurance discrimination.observed
  6. UncertainOneTrust DataGuidanceNo Missouri-specific state-surveillance carve-out affecting private-sector personal-data processing was identified; national-security/law-enforcement exemptions in this space are governed by federal frameworks outside the state consumer-privacy patchwork.observed

#

Solid federal coverage (COPPA, FERPA) exists and applies to Missouri, but no state-specific layer was found for age verification, minor profiling, or dependent adults.

Primary frameworkFederal COPPA (children) and FERPA (students); no Missouri-specific statute
Supervisory authorityMissouri Attorney General
Traffic-light rationale — AmberSolid federal coverage (COPPA, FERPA) exists and applies to Missouri, but no state-specific layer was found for age verification, minor profiling, or dependent adults.

Sub-modules (5)

Age VerificationRed

No Missouri-specific age-verification-for-data-processing statute was identified.

Claims (1):

  • No Missouri-specific statute mandating age verification prior to personal-data processing was identified in this research.

Minor Profiling BansRed

No Missouri-specific statute bans profiling of minors for advertising or other purposes.

Claims (1):

  • No Missouri-specific statute bans profiling of minors for advertising or other commercial purposes.

Education SettingsAmber

FERPA governs student education-record privacy at Missouri educational agencies receiving federal funds.

Claims (1):

  • FERPA gives parents (and eligible students) rights over education records and generally prohibits nonconsensual disclosure of personally identifiable information by educational agencies and institutions, applicable to Missouri schools receiving federal funding.

Dependent AdultsRed

No Missouri-specific dependent-adults data-protection statute was identified beyond general elder-protection and HIPAA overlays; not independently verified in depth in this pass.

Claims (1):

  • No Missouri-specific dependent-adults data-protection statute was identified in this research beyond general elder-protection and federal HIPAA overlays.
Category narrative53 words

Children's and student data in Missouri are governed almost entirely by federal law: COPPA requires parental consent before online operators collect personal information from children under 13, and FERPA governs student education records at federally funded educational agencies. No Missouri-specific age-verification-for-data-processing statute, minor-profiling ban, or dependent-adults data-protection statute was identified in this research.

Sources and claims (5)
  1. ConfirmedFederal Trade CommissionThe federal COPPA Rule requires operators of websites and online services to obtain parental consent before collecting, using, or disclosing personal information from children under 13, applicable to entities operating in Missouri.observed
  2. ConfirmedIAPPFERPA gives parents (and eligible students) rights over education records and generally prohibits nonconsensual disclosure of personally identifiable information by educational agencies and institutions, applicable to Missouri schools receiving federal funding.observed
  3. UncertainOneTrust DataGuidanceNo Missouri-specific statute mandating age verification prior to personal-data processing was identified in this research.observed
  4. ConfirmedOneTrust DataGuidanceNo Missouri-specific statute bans profiling of minors for advertising or other commercial purposes.observed
  5. UncertainOneTrust DataGuidanceNo Missouri-specific dependent-adults data-protection statute was identified in this research beyond general elder-protection and federal HIPAA overlays.observed

#

A real enforcement mechanism and recent AG activity exist, but the private-right-of-action and collective-redress sub-modules are largely absent or unconfirmed.

Primary frameworkMo. Rev. Stat. §407.1500 (AG enforcement)
Supervisory authorityMissouri Attorney General
Traffic-light rationale — AmberA real enforcement mechanism and recent AG activity exist, but the private-right-of-action and collective-redress sub-modules are largely absent or unconfirmed.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

The AG may bring an action for actual damages for willful and knowing violation of §407.1500.

Claims (1):

  • The Missouri Attorney General has exclusive authority to bring an action to obtain actual damages for a willful and knowing violation of §407.1500.

Enforcement Activity IndexAmber

Missouri's AG participates in NAAG-coordinated multistate breach-related settlements; a Missouri-specific standalone enforcement track record under §407.1500 was not independently quantified in this pass.

Claims (1):

  • State attorneys general, including Missouri's, frequently participate in NAAG-coordinated multistate settlements arising from data breaches.

Regulator Funding And CapacityRed

No specific funding or headcount data for the Missouri AG's privacy/consumer-protection enforcement function was identified in this research.

Absence provenance: not recorded. Searched: M, i, s, s, o, u, r, i, , A, t, t, o, r, n, e, y, , G, e, n, e, r, a, l, , c, o, n, s, u, m, e, r, , p, r, o, t, e, c, t, i, o, n, , d, i, v, i, s, i, o, n, , b, u, d, g, e, t, , s, t, a, f, f, i, n, g.

Collective Redress And Class ActionsRed

General Missouri civil-procedure class-action mechanisms may be available for privacy-adjacent common-law claims (e.g., invasion of privacy), but no privacy-specific statutory class-action mechanism was confirmed in this pass.

Absence provenance: not recorded. Searched: M, i, s, s, o, u, r, i, , c, l, a, s, s, , a, c, t, i, o, n, , p, r, i, v, a, c, y, , c, l, a, i, m, s, , R, u, l, e, , 5, 2, ., 0, 8.

Private Right Of ActionRed

The breach statute reserves enforcement to the Attorney General; no general consumer private right of action was identified.

Claims (1):

  • Missouri's breach-notification statute does not appear to create a general private right of action for consumers; enforcement is reserved to the Attorney General.

Recent Developments 180DAmber

Within the last 180 days, the Missouri AG opened an investigation into AI chatbots operated by major technology companies for alleged bias and inaccuracy, an enforcement-adjacent development relevant to the algorithmic-governance module.

Claims (1):

  • The Missouri Attorney General has opened an investigation into AI chatbots operated by major technology companies (including Google, Microsoft, OpenAI, and Meta) for alleged bias and inaccuracy.
Category narrative74 words

The Missouri Attorney General holds exclusive statutory authority to bring actions for willful and knowing violations of §407.1500, seeking actual damages; the statute does not appear to create a general private right of action for consumers. Recent enforcement-adjacent activity includes the Missouri AG's investigation into AI chatbots for alleged bias and inaccuracy, and continued participation in NAAG-coordinated multistate breach settlements. Regulator funding/headcount signals specific to privacy enforcement could not be identified in this pass.

Sources and claims (4)
  1. ConfirmedOneTrust DataGuidanceThe Missouri Attorney General has exclusive authority to bring an action to obtain actual damages for a willful and knowing violation of §407.1500.observed
  2. ProbableOneTrust DataGuidanceMissouri's breach-notification statute does not appear to create a general private right of action for consumers; enforcement is reserved to the Attorney General.observed
  3. ProbableOneTrust DataGuidanceThe Missouri Attorney General has opened an investigation into AI chatbots operated by major technology companies (including Google, Microsoft, OpenAI, and Meta) for alleged bias and inaccuracy.observed
  4. ProbableNAAGState attorneys general, including Missouri's, frequently participate in NAAG-coordinated multistate settlements arising from data breaches.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for United States – Missouri
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-06. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 53 claim(s), 12 source(s) in the cumulative register.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsdeadlines and response windows
Art. 14Data Subject Rightsdeadlines and response windows
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressregulator powers and penalties
Art. 79Enforcement & Redressregulator powers and penalties
Art. 80Enforcement & Redressregulator powers and penalties
Art. 81Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redresscollective redress and class actions
Art. 83Enforcement & Redressprivate right of action
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

All 10 modules were populated. Regulator identity, the core breach-notification statute (§407.1500), and federal sectoral overlays (FTC Act §5, COPPA, FERPA, GLBA) rest on T1/T2 sources. The biometric-data regime (HB 1584) and most gap-findings (absence of lawful bases, DSAR rights, ADM transparency, cookie law, etc.) rest on T3 secondary sources (DataGuidance, IAPP) consistent with the seed's disambiguation note that Missouri lacks a comprehensive statute. Several sub-modules (insurance NAIC-model adoption, AI Non-Sentience Act status, Missouri communications-law specifics, genetic-data and dependent-adults statutes, regulator funding/capacity, collective-redress mechanisms) could not be verified to primary-source standard and are flagged Uncertain with absent_field_provenance.

Unresolved questions (6):

  • Has Missouri adopted any version of the NAIC Insurance Data Security Model Law, and if so under what statute/effective date?
  • What is the precise enactment/effective-date status of Missouri's AI Non-Sentience and Responsibility Act?
  • What is the specific Missouri statute referenced by DataGuidance as governing 'communications' rules, and does it have any eprivacy/telecoms-privacy content?
  • Does Missouri's general civil-procedure class-action rule (analogous to Rule 23/52.08) provide a meaningful collective-redress path for common-law invasion-of-privacy claims, and has it been used in that context?
  • Are there Missouri-specific credit-card or credit-scoring privacy rules beyond federal FCRA, as vaguely referenced by DataGuidance?
  • What are current staffing/funding levels for the Missouri Attorney General's consumer-protection/privacy enforcement function?

Escalate to primary-source review: yes