Missouri does not have a single, comprehensive consumer data-privacy law. Instead, a business that keeps electronic records about Missouri residents is governed by a patchwork: the state's data-breach notification statute (RSMo § 407.1500), sector-specific federal laws for health, financial, and student data, and the general expectation that you maintain reasonable security. The short answer is that you must guard the personal information in your systems, notify people (and sometimes the Attorney General) when it is breached, and you can rely on electronic records and signatures as legally valid under Missouri's version of the UETA.
This guide explains how Missouri treats the privacy, security, and legal validity of electronic records held by businesses — what the breach-notice statute requires, which federal laws fill the gaps, and the practical steps that keep you compliant across all of them.
Missouri's data-breach notification law (RSMo § 407.1500)
The cornerstone of Missouri electronic-records privacy is RSMo § 407.1500. It requires a business that owns or licenses personal information about Missouri residents to notify affected individuals when that information is, or is reasonably believed to have been, accessed or acquired by an unauthorized person in a way that creates a risk of identity theft or other harm.
What "personal information" the statute covers
The statute is triggered by computerized data containing a Missouri resident's first name (or first initial) and last name combined with one or more sensitive data elements, generally:
- Social Security number
- Driver's license or other state-issued ID number
- Financial-account, credit-card, or debit-card number combined with any required security code, access code, or password
- Certain medical or health-insurance information
- A unique electronic identifier or access code that would permit access to an account
Critically, the statute contains an encryption safe harbor: data that is encrypted, redacted, or otherwise altered so it is unreadable or unusable generally does not trigger the notice duty — unless the key or method protecting it was also compromised. Properly encrypting personal data is therefore one of the most effective ways to limit your exposure.
When and how notice is required
On discovering or being notified of a breach, a covered business must notify affected residents without unreasonable delay, consistent with the legitimate needs of law enforcement and the time required to determine the scope of the breach and restore the integrity of the system. The statute describes acceptable methods of notice (written, and in some cases electronic) and may permit substitute notice — through email, website posting, and statewide media — when the cost or number of people affected is very large.
The role of the Attorney General
RSMo § 407.1500 directs that when a breach requires notification to more than a threshold number of Missouri residents, the business must also notify the Missouri Attorney General's office. The Attorney General enforces the statute and can seek penalties for violations under Missouri's consumer-protection authority. Because the exact threshold, timing, and content requirements are set by the statute and can be amended, confirm the current text before relying on a general description.
A separate rule covers vendors: a business that merely maintains personal information on behalf of the owner generally must notify the owner of a breach so the owner can carry out its own notification duties. A vendor's breach is still the data owner's compliance problem.
No comprehensive Missouri consumer-privacy act
Unlike California (CCPA/CPRA), Colorado, and a growing number of other states, Missouri has not enacted a broad, GDPR/CCPA-style consumer data-privacy statute as of this writing. That means Missouri businesses generally do not face across-the-board state-law duties to honor consumer "rights to access, delete, correct, or opt out" of data processing.
Two practical consequences follow. First, your Missouri compliance baseline is the breach-notice statute plus sector-specific federal law — not a single privacy code. Second, other states' laws can still reach you: if you collect personal data from residents of states that do have comprehensive privacy laws, those laws may apply based on where the consumer lives, regardless of where your business sits. Do not assume the absence of a Missouri statute means no obligations exist.
Sector-specific federal laws that fill the gaps
Because Missouri leaves most data-type-specific rules to Washington, the privacy of many electronic records turns on federal law. These are federal statutes and regulations, not Missouri law:
- HIPAA (health data). The federal Health Insurance Portability and Accountability Act and its rules (45 C.F.R. Part 164) govern protected health information held by covered entities — health plans, clearinghouses, and most providers — and their business associates. The HIPAA Security Rule requires administrative, physical, and technical safeguards for electronic PHI, and the Breach Notification Rule requires notice to individuals and the U.S. Department of Health and Human Services.
- Gramm-Leach-Bliley Act (financial data). This federal law governs how financial institutions handle consumers' nonpublic personal information. Its Safeguards Rule requires a written information security program, and its Privacy Rule requires privacy notices and certain opt-out rights.
- FERPA (student records). The federal Family Educational Rights and Privacy Act protects the privacy of student education records held by schools and institutions that receive U.S. Department of Education funding, restricting disclosure without consent.
If one of these federal regimes applies, it sets the privacy and security floor for that category of records — and a single breach can trigger both the federal rule and RSMo § 407.1500 at once.
Reasonable security and record retention
Even outside a sector statute, businesses are expected to maintain reasonable security for the electronic records they hold. The federal FTC Act treats grossly inadequate data security as an unfair practice, and Missouri's Merchandising Practices Act (RSMo § 407.020) provides a parallel state consumer-protection tool. The encryption safe harbor in RSMo § 407.1500 is itself a strong incentive to secure data at rest and in transit.
Record retention cuts both ways. Some records must be kept for set periods (tax, employment, and industry-specific rules often set minimums), but data you no longer need should be securely disposed of — information you do not hold cannot be breached. A clear retention-and-disposal schedule reduces both storage risk and the population of records exposed in any incident.
Validity of electronic records and signatures (UETA)
Missouri has adopted the Uniform Electronic Transactions Act (UETA), codified at RSMo § 432.200–432.295. UETA gives electronic records and electronic signatures the same legal effect as paper documents and handwritten signatures, so long as the parties have agreed to transact electronically.
In practical terms, an electronically signed contract, an emailed acceptance, or a record stored only in digital form is generally not unenforceable merely because it is electronic. UETA also addresses the attribution of electronic signatures and the retention of electronic records — an electronic copy can satisfy a legal record-retention requirement if it accurately reflects the information and remains accessible. (The federal E-SIGN Act provides a parallel rule for interstate and foreign commerce.) UETA does not, however, lower your security obligations: a valid electronic record still must be protected like any other personal information.
Practical compliance steps for a Missouri business
The same building blocks protect you under the breach statute, the federal sector laws, and the reasonable-security expectation at once:
- Inventory your data. Document what personal information you hold, where it lives, who can access it, and how long you keep it. This data map underpins every other step.
- Limit and dispose. Collect and retain less sensitive data, and securely delete what you no longer need on a defined schedule.
- Control access. Use role-based permissions, strong authentication (including multi-factor authentication), and logging so only the right people reach the right records.
- Encrypt. Encrypt personal information at rest and in transit — this both protects the data and may qualify for the RSMo § 407.1500 safe harbor.
- Manage vendors. Require any third party that touches your data to safeguard it, use it only as instructed, and report breaches promptly.
- Build an incident-response plan. Decide in advance who investigates, when counsel and forensics are engaged, and how you will assess notice duties under RSMo § 407.1500 and any applicable federal rule — Missouri requires notice "without unreasonable delay," so a plan written during the breach is too late.
Frequently Asked Questions
Does Missouri have a comprehensive data-privacy law like California's?
No. As of this writing, Missouri has not enacted a broad consumer data-privacy statute comparable to California's CCPA/CPRA or Colorado's law. Missouri businesses rely instead on the data-breach notification statute (RSMo § 407.1500), the FTC Act, and sector-specific federal laws. Confirm the current status, since privacy legislation moves quickly.
What information triggers Missouri's breach-notice law?
RSMo § 407.1500 is triggered by a resident's name combined with a sensitive element — a Social Security number, driver's license or state-ID number, financial-account or card number with its access code, or certain medical or health-insurance information. Properly encrypted or redacted data generally does not trigger the duty unless the protective method was also compromised.
When do I have to notify the Missouri Attorney General?
When a breach requires notifying more than a statutory threshold number of Missouri residents, RSMo § 407.1500 also requires notice to the Missouri Attorney General's office, which enforces the statute. Affected individuals must be notified "without unreasonable delay." Verify the current threshold and timing in the operative text.
Are electronic records and e-signatures legally valid in Missouri?
Yes. Under Missouri's adoption of the UETA (RSMo § 432.200–432.295), electronic records and electronic signatures have the same legal effect as paper and ink, provided the parties agreed to transact electronically. The federal E-SIGN Act provides a parallel rule for interstate transactions.
Do HIPAA and FERPA come from Missouri law?
No. HIPAA (health data, 45 C.F.R. Part 164), the Gramm-Leach-Bliley Act (financial data), and FERPA (student records) are all federal laws. They apply on top of Missouri's breach-notice statute, and a single incident can trigger both a federal rule and RSMo § 407.1500.
A vendor that stores our data was breached. Do we still notify anyone?
Quite possibly. Under RSMo § 407.1500, the business that owns or licenses the personal information generally keeps the notification duty even when a vendor holding the data suffers the breach; the vendor must alert the owner so it can notify affected residents. This is why vendor contracts should require prompt breach notice.
Legal Disclaimer
This guide provides general legal information about Missouri and federal privacy law as it applies to electronic records, and is not legal advice. It does not create an attorney-client relationship. Your obligations depend on your specific data, industry, and the current text of the applicable statutes and regulations; consult a qualified Missouri attorney about your situation, and act promptly if you suspect a data breach.