#
A narrow but real state statute (breach notification) and clear regulator identity exist, but there is no comprehensive material/territorial scope framework, hence amber rather than green.
Sub-modules (5)
Regulator And AuthorityAmber
The Missouri Attorney General is the sole state authority with statutory enforcement power over §407.1500; there is no dedicated state data-protection authority analogous to a DPA.
Claims (1):
- Missouri has no comprehensive consumer-privacy statute; the Missouri Attorney General enforces general consumer-protection law and the state breach-notification statute in this space.
Act And InstrumentsAmber
The principal instrument is Mo. Rev. Stat. §407.1500; there is no Missouri-equivalent of GDPR/CCPA.
Claims (2):
- The primary state-level data-protection instrument in Missouri is the data-breach notification statute at Mo. Rev. Stat. §407.1500, Chapter 407, Title XXVI.
- Federal Trade Commission Act Section 5 unfair-or-deceptive-practices authority applies nationally, including to Missouri entities, as a general privacy-and-security enforcement baseline in the absence of a state omnibus law.
Material ScopeRed
Material scope is narrow, tracking identity-theft/financial-fraud data elements typical of first-generation US breach laws rather than a broad 'personal data' definition.
Claims (1):
- US state breach-notification statutes, including Missouri's, generally define covered personal information narrowly around identity-theft and financial-fraud data elements, in contrast to the broader definitions used in comprehensive state privacy laws.
Territorial ScopeAmber
The breach statute applies based on the residency of affected individuals (Missouri residents) and a 1,000-resident AG-notification threshold, rather than a controller-establishment test.
Claims (1):
- Notification under Missouri's breach statute must be provided without undue delay to consumers and to the Missouri Attorney General where the breach involves the information of more than 1,000 Missouri residents.
Regulator Registration And FilingRed
No general controller registration or filing scheme exists; AG notice is triggered only by the breach threshold.
Claims (1):
- Missouri imposes no general controller registration or filing regime; the only filing-adjacent duty is threshold-triggered breach notice to the Attorney General.
Sources and claims (6)
- ConfirmedOneTrust DataGuidance — Missouri has no comprehensive consumer-privacy statute; the Missouri Attorney General enforces general consumer-protection law and the state breach-notification statute in this space.observed
- ConfirmedOneTrust DataGuidance — The primary state-level data-protection instrument in Missouri is the data-breach notification statute at Mo. Rev. Stat. §407.1500, Chapter 407, Title XXVI.observed
- ConfirmedFederal Trade Commission — Federal Trade Commission Act Section 5 unfair-or-deceptive-practices authority applies nationally, including to Missouri entities, as a general privacy-and-security enforcement baseline in the absence of a state omnibus law.observed
- ProbableIAPP — US state breach-notification statutes, including Missouri's, generally define covered personal information narrowly around identity-theft and financial-fraud data elements, in contrast to the broader definitions used in comprehensive state privacy laws.observed
- ConfirmedOneTrust DataGuidance — Notification under Missouri's breach statute must be provided without undue delay to consumers and to the Missouri Attorney General where the breach involves the information of more than 1,000 Missouri residents.observed
- ConfirmedOneTrust DataGuidance — Missouri imposes no general controller registration or filing regime; the only filing-adjacent duty is threshold-triggered breach notice to the Attorney General.observed