{
  "type": "practice-guide",
  "canonical": "https://openagreements.org/practice-guides/privacy/us/missouri",
  "links": [
    {
      "rel": "self",
      "href": "https://openagreements.org/practice-guides/privacy/us/missouri.json",
      "type": "application/json"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/missouri",
      "type": "text/html"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/missouri/markdown",
      "type": "text/markdown"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/missouri/json",
      "type": "application/json"
    }
  ],
  "data": {
    "topic": "privacy",
    "state": "missouri",
    "frontmatter": {
      "title": "Missouri Consumer Privacy Law",
      "description": "Missouri has no omnibus consumer-privacy statute; the main commercial spine is breach notice, MMPA deception, and the insurance-sector IDSA.",
      "state": "Missouri",
      "lastReviewed": "2026-06-11",
      "license": "CC BY 4.0",
      "authors": [
        "steven-obiajulu"
      ],
      "summary": {
        "keyLaw": "Mo. Rev. Stat. § 407.1500 (breach notification) plus the Merchandising Practices Act (§§ 407.010–407.025) and, for insurance licensees, the Insurance Data Security Act (§§ 375.1400–375.1427, effective January 1, 2026) — Missouri has no comprehensive consumer-privacy statute",
        "appliesTo": "Breach statute: any person that owns or licenses personal information of Missouri residents, or that conducts business in Missouri and owns or licenses a resident's personal information, with no size threshold. MMPA: anyone selling or advertising merchandise — defined to include services and intangibles — in or from Missouri. Insurance Data Security Act: persons licensed or registered under Missouri insurance law",
        "privacyPolicyRequired": "No general Missouri mandate fixes a privacy policy's contents — they are driven by FTC Act § 5 and the sectoral overlay (GLBA, HIPAA, COPPA), with the MMPA supplying the state deception hook for a policy that misstates actual practices; an insurance licensee must hand its privacy policy to the insurance director after a cybersecurity event",
        "privateRightOfAction": "Not under the breach statute (the Attorney General has exclusive authority, with a civil penalty up to $150,000 per breach) and expressly none under the Insurance Data Security Act; but MMPA § 407.025 gives consumers a private action — punitive damages, fee-shifting, and class actions included — subject to heightened reasonable-consumer and objective-damages proof requirements added in 2020",
        "regulator": "Missouri Attorney General (breach statute and MMPA); Director of the Department of Commerce and Insurance (Insurance Data Security Act)",
        "bottomLine": "Missouri has not enacted a comprehensive consumer-privacy law. The 2026 session saw biometric and privacy-adjacent bills, but no omnibus access/delete/correct/opt-out framework passed before the May 15, 2026 adjournment, so the main commercial state framework is the breach-notification statute, the MMPA's deception rules and qualified private right of action, and, for insurance licensees, the Insurance Data Security Act's phased duties; everything else rides the federal overlay.",
        "lawCoverage": "baseline",
        "policyMandate": "none",
        "consumersCanSue": "broad",
        "sensitiveDataConsent": "none",
        "universalOptOutSignal": "notRequired"
      },
      "about": [
        "Missouri consumer privacy law",
        "Missouri data breach notification 407.1500",
        "Missouri Merchandising Practices Act privacy",
        "MMPA private right of action ascertainable loss",
        "Missouri Insurance Data Security Act 375.1400",
        "Missouri four business day cybersecurity notice",
        "Missouri privacy policy requirements",
        "Missouri Attorney General privacy enforcement",
        "Missouri no comprehensive privacy law",
        "Missouri vendor data security contracts"
      ],
      "translations": [
        {
          "language": "中文",
          "status": "planned"
        },
        {
          "language": "Español",
          "status": "planned"
        },
        {
          "language": "Português",
          "status": "planned"
        },
        {
          "language": "Deutsch",
          "status": "planned"
        }
      ]
    },
    "questions": [
      {
        "slug": "which-privacy-laws-apply",
        "label": "Which privacy laws apply to your business in Missouri?",
        "heading": "Which privacy laws apply to your business in Missouri?",
        "answerText": "There is no comprehensive Missouri consumer-privacy law. The main commercial privacy spine is three state statutes, with narrower Missouri sectoral rules still possible outside this workflow. The breach-notification statute applies to any person that owns or licenses personal information of Missouri residents, or that conducts business in Missouri and owns or licenses a resident's personal information, with no revenue or volume threshold. The Merchandising Practices Act (MMPA) makes deception, fraud, misrepresentation, unfair practices, and material omissions in connection with the sale or advertisement of merchandise unlawful — the hook that reaches privacy promises. And for the insurance sector, the Insurance Data Security Act establishes the exclusive state standards for licensees' data security, cybersecurity-event investigation, and notification to the director.",
        "sources": [
          {
            "id": "stat-1500-trigger",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Mo. Rev. Stat. § 407.1500",
            "citation": "Mo. Rev. Stat. § 407.1500.2(1).",
            "url": "https://revisor.mo.gov/main/OneSection.aspx?section=407.1500",
            "proposition": "Missouri's breach statute applies to any person that owns or licenses personal information of Missouri residents, or that conducts business in Missouri and owns or licenses a resident's personal information, with no size threshold.",
            "verbatimQuote": "Any person that owns or licenses personal information of residents of Missouri or any person that conducts business in Missouri that owns or licenses personal information in any form of a resident of Missouri shall provide notice to the affected consumer that there has been a breach of security following discovery or notification of the breach.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/missouri#src-stat-1500-trigger"
          },
          {
            "id": "stat-020-unlawful",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Mo. Rev. Stat. § 407.020",
            "citation": "Mo. Rev. Stat. § 407.020.1.",
            "url": "https://revisor.mo.gov/main/OneSection.aspx?section=407.020",
            "proposition": "The MMPA declares deception, fraud, false pretense, misrepresentation, unfair practices, and the concealment or omission of material facts in connection with the sale or advertisement of merchandise in or from Missouri to be unlawful practices.",
            "verbatimQuote": "The act, use or employment by any person of any deception, fraud, false pretense, false promise, misrepresentation, unfair practice or the concealment, suppression, or omission of any material fact in connection with the sale or advertisement of any merchandise in trade or commerce or the solicitation of any funds for any charitable purpose, as defined in section 407.453, in or from the state of Missouri, is declared to be an unlawful practice.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/missouri#src-stat-020-unlawful"
          },
          {
            "id": "stat-1400-exclusive",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Mo. Rev. Stat. § 375.1400",
            "citation": "Mo. Rev. Stat. § 375.1400.2.",
            "url": "https://revisor.mo.gov/main/OneSection.aspx?section=375.1400",
            "proposition": "The Insurance Data Security Act establishes the exclusive state standards applicable to insurance licensees for data security, cybersecurity-event investigation, and notification to the director.",
            "verbatimQuote": "Notwithstanding any other provision of law, sections 375.1400 to 375.1427 establish the exclusive state standards applicable to licensees for data security, the investigation of a cybersecurity event as defined in section 375.1402, and notification to the director.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/missouri#src-stat-1400-exclusive"
          },
          {
            "id": "stat-010-merchandise",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Mo. Rev. Stat. § 407.010",
            "citation": "Mo. Rev. Stat. § 407.010(4).",
            "url": "https://revisor.mo.gov/main/OneSection.aspx?section=407.010",
            "proposition": "The MMPA defines merchandise to include services and intangibles, which is what lets the act reach data-driven consumer services.",
            "verbatimQuote": "any objects, wares, goods, commodities, intangibles, real estate or services",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/missouri#src-stat-010-merchandise"
          },
          {
            "id": "stat-hb974-effective",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Mo. Rev. Stat. § 375.1400 (enactment history)",
            "citation": "Mo. Rev. Stat. § 375.1400 (history note; eff. Jan. 1, 2026).",
            "url": "https://revisor.mo.gov/main/OneSection.aspx?section=375.1400",
            "proposition": "The Insurance Data Security Act was enacted in 2025 as H.B. 974 and took effect January 1, 2026.",
            "verbatimQuote": "(L. 2025 H.B. 974, et al.) Effective 1-01-26; see § 375.1427",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/missouri#src-stat-hb974-effective"
          },
          {
            "id": "stat-idsa-phase-in",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Mo. Rev. Stat. § 375.1427",
            "citation": "Mo. Rev. Stat. § 375.1427.",
            "url": "https://revisor.mo.gov/main/OneSection.aspx?section=375.1427",
            "proposition": "The Insurance Data Security Act took effect January 1, 2026, with § 375.1405 implementation due January 1, 2027 and § 375.1405.6 third-party-service-provider implementation due January 1, 2028.",
            "verbatimQuote": "Sections 375.1400 to 375.1427 shall take effect on January 1, 2026. Licensees shall have until January 1, 2027, to implement section 375.1405 and until January 1, 2028, to implement subsection 6 of section 375.1405.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/missouri#src-stat-idsa-phase-in"
          }
        ]
      },
      {
        "slug": "privacy-policy-contents",
        "label": "What must your Missouri privacy policy contain?",
        "heading": "What must your Missouri privacy policy contain?",
        "answerText": "No Missouri statute requires a general consumer privacy policy or fixes its contents. The governing rule is that whatever you publish must be true: under Section 5 of the FTC Act, unfair or deceptive acts or practices in or affecting commerce are unlawful, and the MMPA makes the same conduct actionable as a matter of Missouri law when the misstatement, concealment, or omission of a material fact occurs in connection with the sale or advertisement of merchandise. A privacy policy that misdescribes how you collect, use, share, retain, or secure data is exposure under both.",
        "sources": [
          {
            "id": "fed-ftc5-deceptive",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "FTC Act § 5",
            "citation": "15 U.S.C. § 45(a)(1).",
            "url": "https://www.law.cornell.edu/uscode/text/15/45",
            "deepLink": "https://www.law.cornell.edu/uscode/text/15/45#:~:text=Unfair%20methods%20of%20competition%20in,commerce%2C%20are%20hereby%20declared%20unlawful.",
            "proposition": "Section 5 of the FTC Act declares unfair or deceptive acts or practices in or affecting commerce unlawful, which reaches a privacy policy that misstates a business's actual data practices.",
            "verbatimQuote": "Unfair methods of competition in or affecting commerce, and unfair or deceptive acts or practices in or affecting commerce, are hereby declared unlawful.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/missouri#src-fed-ftc5-deceptive"
          },
          {
            "id": "q2-mmpa-deception",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Mo. Rev. Stat. § 407.020",
            "citation": "Mo. Rev. Stat. § 407.020.1.",
            "url": "https://revisor.mo.gov/main/OneSection.aspx?section=407.020",
            "proposition": "The MMPA makes deception, misrepresentation, and the concealment or omission of material facts in connection with the sale or advertisement of merchandise unlawful — the state-law hook for a privacy policy that misstates actual practices.",
            "verbatimQuote": "The act, use or employment by any person of any deception, fraud, false pretense, false promise, misrepresentation, unfair practice or the concealment, suppression, or omission of any material fact in connection with the sale or advertisement of any merchandise in trade or commerce or the solicitation of any funds for any charitable purpose, as defined in section 407.453, in or from the state of Missouri, is declared to be an unlawful practice.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/missouri#src-q2-mmpa-deception"
          },
          {
            "id": "fed-glba-notice",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "GLBA privacy-notice obligation",
            "citation": "15 U.S.C. § 6802(a).",
            "url": "https://www.law.cornell.edu/uscode/text/15/6802",
            "deepLink": "https://www.law.cornell.edu/uscode/text/15/6802#:~:text=Except%20as%20otherwise%20provided%20in,section%206803%20of%20this%20title.",
            "proposition": "A financial institution may not disclose nonpublic personal information to a nonaffiliated third party unless it has provided the consumer a GLBA-compliant privacy notice.",
            "verbatimQuote": "Except as otherwise provided in this subchapter, a financial institution may not, directly or through any affiliate, disclose to a nonaffiliated third party any nonpublic personal information, unless such financial institution provides or has provided to the consumer a notice that complies with section 6803 of this title.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/missouri#src-fed-glba-notice"
          },
          {
            "id": "fed-hipaa-notice",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "HIPAA Notice of Privacy Practices",
            "citation": "45 C.F.R. § 164.520(a)(1).",
            "url": "https://www.law.cornell.edu/cfr/text/45/164.520",
            "deepLink": "https://www.law.cornell.edu/cfr/text/45/164.520#:~:text=an%20individual%20has%20a%20right,respect%20to%20protected%20health%20information",
            "proposition": "A HIPAA covered entity must give individuals a notice describing the uses and disclosures of their protected health information and their rights and the entity's legal duties.",
            "verbatimQuote": "an individual has a right to adequate notice of the uses and disclosures of protected health information that may be made by the covered entity, and of the individual's rights and the covered entity's legal duties with respect to protected health information",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/missouri#src-fed-hipaa-notice"
          },
          {
            "id": "stat-1410-policy-copy",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Mo. Rev. Stat. § 375.1410",
            "citation": "Mo. Rev. Stat. § 375.1410.2(12).",
            "url": "https://revisor.mo.gov/main/OneSection.aspx?section=375.1410",
            "proposition": "After a reportable cybersecurity event, an insurance licensee must provide the director a copy of its privacy policy and a statement of the steps it will take to investigate and notify affected consumers.",
            "verbatimQuote": "A copy of the licensee's privacy policy and a statement outlining the steps the licensee will take to investigate and notify consumers affected by the cybersecurity event",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/missouri#src-stat-1410-policy-copy"
          }
        ]
      },
      {
        "slug": "vendor-contracts",
        "label": "What must your contracts with vendors say?",
        "heading": "What must your contracts with vendors say?",
        "answerText": "Missouri has no omnibus data-processing-agreement requirement — no state statute prescribes controller-to-processor terms, audit rights, deletion clauses, or subprocessor flow-downs for general private-sector contracts. The two state-law touchpoints are narrow: the breach statute requires any person that maintains records it does not own to notify the owner or licensee of a breach immediately following discovery, and the Insurance Data Security Act requires licensees to make their third-party service providers implement appropriate administrative, technical, and physical safeguards, with that vendor-safeguards duty phased to January 1, 2028.",
        "sources": [
          {
            "id": "q3-breach-vendor",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Mo. Rev. Stat. § 407.1500",
            "citation": "Mo. Rev. Stat. § 407.1500.2(2).",
            "url": "https://revisor.mo.gov/main/OneSection.aspx?section=407.1500",
            "proposition": "A person that maintains records containing Missouri residents' personal information that it does not own or license must notify the owner or licensee immediately following discovery of a breach.",
            "verbatimQuote": "Any person that maintains or possesses records or data containing personal information of residents of Missouri that the person does not own or license, or any person that conducts business in Missouri that maintains or possesses records or data containing personal information of a resident of Missouri that the person does not own or license, shall notify the owner or licensee of the information of any breach of security immediately following discovery of the breach, consistent with the legitimate needs of law enforcement as provided in this section.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/missouri#src-q3-breach-vendor"
          },
          {
            "id": "stat-1405-vendor",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Mo. Rev. Stat. § 375.1405",
            "citation": "Mo. Rev. Stat. § 375.1405.6(2).",
            "url": "https://revisor.mo.gov/main/OneSection.aspx?section=375.1405",
            "proposition": "An insurance licensee must require its third-party service providers to implement appropriate administrative, technical, and physical measures protecting the information systems and nonpublic information they can access or hold.",
            "verbatimQuote": "A licensee shall require a third-party service provider to implement appropriate administrative, technical, and physical measures to protect and secure the information systems and nonpublic information that are accessible to, or held by, the third-party service provider.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/missouri#src-stat-1405-vendor"
          },
          {
            "id": "q3-idsa-phase-in",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Mo. Rev. Stat. § 375.1427",
            "citation": "Mo. Rev. Stat. § 375.1427.",
            "url": "https://revisor.mo.gov/main/OneSection.aspx?section=375.1427",
            "proposition": "The Insurance Data Security Act took effect January 1, 2026, with § 375.1405 implementation due January 1, 2027 and § 375.1405.6 third-party-service-provider implementation due January 1, 2028.",
            "verbatimQuote": "Sections 375.1400 to 375.1427 shall take effect on January 1, 2026. Licensees shall have until January 1, 2027, to implement section 375.1405 and until January 1, 2028, to implement subsection 6 of section 375.1405.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/missouri#src-q3-idsa-phase-in"
          },
          {
            "id": "stat-1405-diligence",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Mo. Rev. Stat. § 375.1405",
            "citation": "Mo. Rev. Stat. § 375.1405.6(1).",
            "url": "https://revisor.mo.gov/main/OneSection.aspx?section=375.1405",
            "proposition": "An insurance licensee must exercise due diligence in selecting its third-party service providers.",
            "verbatimQuote": "A licensee shall exercise due diligence in selecting its third-party service provider.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/missouri#src-stat-1405-diligence"
          },
          {
            "id": "fed-glba-safeguards",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "GLBA Safeguards Rule",
            "citation": "16 C.F.R. § 314.4(f)(2).",
            "url": "https://www.law.cornell.edu/cfr/text/16/314.4",
            "deepLink": "https://www.law.cornell.edu/cfr/text/16/314.4#:~:text=Requiring%20your%20service%20providers%20by,implement%20and%20maintain%20such%20safeguards",
            "proposition": "The GLBA Safeguards Rule requires a financial institution to oversee its service providers, including by requiring them by contract to implement and maintain appropriate safeguards for customer information.",
            "verbatimQuote": "Requiring your service providers by contract to implement and maintain such safeguards",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/missouri#src-fed-glba-safeguards"
          },
          {
            "id": "fed-hipaa-baa",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "HIPAA Business Associate Contracts",
            "citation": "45 C.F.R. § 164.504(e)(2).",
            "url": "https://www.law.cornell.edu/cfr/text/45/164.504",
            "deepLink": "https://www.law.cornell.edu/cfr/text/45/164.504#:~:text=A%20contract%20between%20the%20covered,with%20respect%20to%20such%20information",
            "proposition": "HIPAA requires a business-associate contract to establish permitted uses and disclosures, require safeguards, require breach reporting to the covered entity, and flow the same restrictions and conditions to subcontractors.",
            "verbatimQuote": "A contract between the covered entity and a business associate must: (i) Establish the permitted and required uses and disclosures of protected health information by the business associate. The contract may not authorize the business associate to use or further disclose the information in a manner that would violate the requirements of this subpart, if done by the covered entity, except that: (A) The contract may permit the business associate to use and disclose protected health information for the proper management and administration of the business associate, as provided in paragraph (e)(4) of this section; and (B) The contract may permit the business associate to provide data aggregation services relating to the health care operations of the covered entity. (ii) Provide that the business associate will: (A) Not use or further disclose the information other than as permitted or required by the contract or as required by law; (B) Use appropriate safeguards and comply, where applicable, with subpart C of this part with respect to electronic protected health information, to prevent use or disclosure of the information other than as provided for by its contract; (C) Report to the covered entity any use or disclosure of the information not provided for by its contract of which it becomes aware, including breaches of unsecured protected health information as required by § 164.410; (D) In accordance with § 164.502(e)(1)(ii), ensure that any subcontractors that create, receive, maintain, or transmit protected health information on behalf of the business associate agree to the same restrictions and conditions that apply to the business associate with respect to such information",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/missouri#src-fed-hipaa-baa"
          }
        ]
      },
      {
        "slug": "breach-notification",
        "label": "When must you notify people of a data breach in Missouri?",
        "heading": "When must you notify people of a data breach in Missouri?",
        "answerText": "Any person that owns or licenses personal information of Missouri residents — or that conducts business in Missouri and owns or licenses a resident's personal information — must notify the affected consumer of a breach of security following discovery or notification of the breach. The disclosure must be made without unreasonable delay, consistent with the legitimate needs of law enforcement and with the measures needed to determine the breach's scope and restore the system's integrity. If you notify more than 1,000 consumers at one time, you must also notify the Attorney General's office and the nationwide consumer reporting agencies, again without unreasonable delay.",
        "sources": [
          {
            "id": "q4-breach-trigger",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Mo. Rev. Stat. § 407.1500",
            "citation": "Mo. Rev. Stat. § 407.1500.2(1).",
            "url": "https://revisor.mo.gov/main/OneSection.aspx?section=407.1500",
            "proposition": "Any person that owns or licenses Missouri residents' personal information must notify affected consumers of a breach of security following discovery or notification of the breach.",
            "verbatimQuote": "Any person that owns or licenses personal information of residents of Missouri or any person that conducts business in Missouri that owns or licenses personal information in any form of a resident of Missouri shall provide notice to the affected consumer that there has been a breach of security following discovery or notification of the breach.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/missouri#src-q4-breach-trigger"
          },
          {
            "id": "q4-breach-timing",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Mo. Rev. Stat. § 407.1500",
            "citation": "Mo. Rev. Stat. § 407.1500.2(1).",
            "url": "https://revisor.mo.gov/main/OneSection.aspx?section=407.1500",
            "proposition": "Breach notice must be made without unreasonable delay, consistent with law enforcement's legitimate needs and with measures necessary to determine the breach's scope and restore the system.",
            "verbatimQuote": "The disclosure notification shall be: (a) Made without unreasonable delay; (b) Consistent with the legitimate needs of law enforcement, as provided in this section; and (c) Consistent with any measures necessary to determine sufficient contact information and to determine the scope of the breach and restore the reasonable integrity, security, and confidentiality of the data system.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/missouri#src-q4-breach-timing"
          },
          {
            "id": "q4-personal-information",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Mo. Rev. Stat. § 407.1500",
            "citation": "Mo. Rev. Stat. § 407.1500.1(9).",
            "url": "https://revisor.mo.gov/main/OneSection.aspx?section=407.1500",
            "proposition": "Missouri defines personal information as a resident's name combined with listed unencrypted, unredacted, or otherwise readable data elements, including SSN, government ID, financial-account credentials, medical information, and health-insurance information.",
            "verbatimQuote": "(9) \"Personal information\", an individual's first name or first initial and last name in combination with any one or more of the following data elements that relate to the individual if any of the data elements are not encrypted, redacted, or otherwise altered by any method or technology in such a manner that the name or data elements are unreadable or unusable: (a) Social Security number; (b) Driver's license number or other unique identification number created or collected by a government body; (c) Financial account number, credit card number, or debit card number in combination with any required security code, access code, or password that would permit access to an individual's financial account; (d) Unique electronic identifier or routing code, in combination with any required security code, access code, or password that would permit access to an individual's financial account; (e) Medical information; or (f) Health insurance information.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/missouri#src-q4-personal-information"
          },
          {
            "id": "q4-breach-definition",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Mo. Rev. Stat. § 407.1500",
            "citation": "Mo. Rev. Stat. § 407.1500.1(1).",
            "url": "https://revisor.mo.gov/main/OneSection.aspx?section=407.1500",
            "proposition": "A breach is unauthorized access to and unauthorized acquisition of personal information maintained in computerized form that compromises the information's security, confidentiality, or integrity.",
            "verbatimQuote": "unauthorized access to and unauthorized acquisition of personal information maintained in computerized form by a person that compromises the security, confidentiality, or integrity of the personal information.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/missouri#src-q4-breach-definition"
          },
          {
            "id": "q4-breach-contents",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Mo. Rev. Stat. § 407.1500",
            "citation": "Mo. Rev. Stat. § 407.1500.2(4).",
            "url": "https://revisor.mo.gov/main/OneSection.aspx?section=407.1500",
            "proposition": "The consumer notice must at minimum describe the incident in general terms, the type of personal information obtained, a contact number if one exists, consumer-reporting-agency contacts, and vigilance advice.",
            "verbatimQuote": "The notice shall at minimum include a description of the following: (a) The incident in general terms; (b) The type of personal information that was obtained as a result of the breach of security; (c) A telephone number that the affected consumer may call for further information and assistance, if one exists; (d) Contact information for consumer reporting agencies; (e) Advice that directs the affected consumer to remain vigilant by reviewing account statements and monitoring free credit reports.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/missouri#src-q4-breach-contents"
          },
          {
            "id": "q4-breach-methods",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Mo. Rev. Stat. § 407.1500",
            "citation": "Mo. Rev. Stat. § 407.1500.2(6)-(7).",
            "url": "https://revisor.mo.gov/main/OneSection.aspx?section=407.1500",
            "proposition": "Missouri permits written, electronic, telephonic, or substitute breach notice; substitute notice is available above the $100,000 cost threshold, above 150,000 affected consumers, where contact information or consent is lacking, or where consumers cannot be identified, and it requires email when available, website posting if maintained, and statewide media notice.",
            "verbatimQuote": "For purposes of this section, notice to affected consumers shall be provided by one of the following methods: (a) Written notice; (b) Electronic notice for those consumers for whom the person has a valid email address and who have agreed to receive communications electronically, if the notice provided is consistent with the provisions of 15 U.S.C. Section 7001 regarding electronic records and signatures for notices legally required to be in writing; (c) Telephonic notice, if such contact is made directly with the affected consumers; or (d) Substitute notice",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/missouri#src-q4-breach-methods"
          },
          {
            "id": "q4-breach-ag-cra",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Mo. Rev. Stat. § 407.1500",
            "citation": "Mo. Rev. Stat. § 407.1500.2(8).",
            "url": "https://revisor.mo.gov/main/OneSection.aspx?section=407.1500",
            "proposition": "When notice goes to more than 1,000 consumers at one time, the person must also notify the Attorney General's office and the nationwide consumer reporting agencies of the timing, distribution, and content of the notice.",
            "verbatimQuote": "In the event a person provides notice to more than one thousand consumers at one time pursuant to this section, the person shall notify, without unreasonable delay, the attorney general's office and all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis, as defined in 15 U.S.C. Section 1681a(p), of the timing, distribution, and content of the notice.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/missouri#src-q4-breach-ag-cra"
          },
          {
            "id": "q4-breach-harm-exception",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Mo. Rev. Stat. § 407.1500",
            "citation": "Mo. Rev. Stat. § 407.1500.2(5).",
            "url": "https://revisor.mo.gov/main/OneSection.aspx?section=407.1500",
            "proposition": "Notification is not required if an appropriate investigation or law-enforcement consultation determines that identity theft or other fraud is not reasonably likely to occur, with the determination documented in writing and kept five years.",
            "verbatimQuote": "Notwithstanding subdivisions (1) and (2) of this subsection, notification is not required if, after an appropriate investigation by the person or after consultation with the relevant federal, state, or local agencies responsible for law enforcement, the person determines that a risk of identity theft or other fraud to any consumer is not reasonably likely to occur as a result of the breach. Such a determination shall be documented in writing and the documentation shall be maintained for five years.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/missouri#src-q4-breach-harm-exception"
          },
          {
            "id": "q4-breach-penalty",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Mo. Rev. Stat. § 407.1500",
            "citation": "Mo. Rev. Stat. § 407.1500.4.",
            "url": "https://revisor.mo.gov/main/OneSection.aspx?section=407.1500",
            "proposition": "The Attorney General has exclusive authority to seek actual damages for a willful and knowing violation and a civil penalty of up to $150,000 per breach or per series of similar breaches discovered in a single investigation.",
            "verbatimQuote": "The attorney general shall have exclusive authority to bring an action to obtain actual damages for a willful and knowing violation of this section and may seek a civil penalty not to exceed one hundred fifty thousand dollars per breach of the security of the system or series of breaches of a similar nature that are discovered in a single investigation.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/missouri#src-q4-breach-penalty"
          }
        ]
      },
      {
        "slug": "insurance-data-security",
        "label": "What does Missouri's Insurance Data Security Act require of insurance licensees?",
        "heading": "What does Missouri's Insurance Data Security Act require of insurance licensees?",
        "answerText": "If you are licensed, authorized, or registered under Missouri insurance law, a dedicated regime is already effective: the Insurance Data Security Act, enacted in 2025 as H.B. 974, took effect January 1, 2026. Its headline operational duty is live now: a licensee must notify the director of the Department of Commerce and Insurance as promptly as practicable, but in no event later than four business days, from a determination that a qualifying cybersecurity event has occurred. Its structural security-program duty is phased: § 375.1405 implementation runs to January 1, 2027, and third-party-service-provider safeguards under § 375.1405.6 run to January 1, 2028.",
        "sources": [
          {
            "id": "q5-idsa-effective",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Mo. Rev. Stat. § 375.1400 (enactment history)",
            "citation": "Mo. Rev. Stat. § 375.1400 (history note; eff. Jan. 1, 2026).",
            "url": "https://revisor.mo.gov/main/OneSection.aspx?section=375.1400",
            "proposition": "The Insurance Data Security Act was enacted in 2025 as H.B. 974 and took effect January 1, 2026.",
            "verbatimQuote": "(L. 2025 H.B. 974, et al.) Effective 1-01-26; see § 375.1427",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/missouri#src-q5-idsa-effective"
          },
          {
            "id": "q5-idsa-phase-in",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Mo. Rev. Stat. § 375.1427",
            "citation": "Mo. Rev. Stat. § 375.1427.",
            "url": "https://revisor.mo.gov/main/OneSection.aspx?section=375.1427",
            "proposition": "The Insurance Data Security Act took effect January 1, 2026, with § 375.1405 implementation due January 1, 2027 and § 375.1405.6 third-party-service-provider implementation due January 1, 2028.",
            "verbatimQuote": "Sections 375.1400 to 375.1427 shall take effect on January 1, 2026. Licensees shall have until January 1, 2027, to implement section 375.1405 and until January 1, 2028, to implement subsection 6 of section 375.1405.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/missouri#src-q5-idsa-phase-in"
          },
          {
            "id": "q5-idsa-4day",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Mo. Rev. Stat. § 375.1410",
            "citation": "Mo. Rev. Stat. § 375.1410.1.",
            "url": "https://revisor.mo.gov/main/OneSection.aspx?section=375.1410",
            "proposition": "A licensee must notify the director as promptly as practicable, and no later than four business days, after determining that a cybersecurity event involving nonpublic information has occurred and one of the statutory criteria is met.",
            "verbatimQuote": "Each licensee shall notify the director as promptly as practicable, but in no event later than four business days, from a determination that a cybersecurity event involving nonpublic information that is in the possession of a licensee has occurred when either of the following criteria has been met:",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/missouri#src-q5-idsa-4day"
          },
          {
            "id": "q5-idsa-criteria",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Mo. Rev. Stat. § 375.1410",
            "citation": "Mo. Rev. Stat. § 375.1410.1(1)-(2).",
            "url": "https://revisor.mo.gov/main/OneSection.aspx?section=375.1410",
            "proposition": "Director notice is required when Missouri is the licensee's domicile or home state and material harm is reasonably likely, or when the event involves at least 250 Missouri consumers and either other government or supervisory notice is required or material harm is reasonably likely.",
            "verbatimQuote": "(1) This state is the licensee's state of domicile, in the case of an insurer, or this state is the licensee's home state, in the case of a producer, as those terms are defined in section 375.012, and the cybersecurity event has a reasonable likelihood of materially harming a consumer residing in this state or a reasonable likelihood of materially harming any material part of the normal operations of the licensee; or (2) The licensee reasonably believes that the nonpublic information involved is of two hundred fifty or more consumers residing in this state and is either of the following: (a) A cybersecurity event impacting the licensee of which notice is required to be provided to any government body, self-regulatory agency, or any other supervisory body under any state or federal law; or (b) A cybersecurity event that has a reasonable likelihood of materially harming: a. Any consumer residing in this state; or b. Any material part of the normal operations of the licensee.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/missouri#src-q5-idsa-criteria"
          },
          {
            "id": "q5-idsa-program",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Mo. Rev. Stat. § 375.1405",
            "citation": "Mo. Rev. Stat. § 375.1405.1.",
            "url": "https://revisor.mo.gov/main/OneSection.aspx?section=375.1405",
            "proposition": "Each licensee must develop, implement, and maintain a comprehensive written information security program, scaled to its size, complexity, and data sensitivity, based on its risk assessment, with administrative, technical, and physical safeguards.",
            "verbatimQuote": "Commensurate with the size and complexity of the licensee; the nature and scope of the licensee's activities, including its use of third-party service providers; and the sensitivity of the nonpublic information used by the licensee or in the licensee's possession, custody, or control, each licensee shall develop, implement, and maintain a comprehensive written information security program that is based on the licensee's risk assessment and that contains administrative, technical, and physical safeguards for the protection of nonpublic information and the licensee's information system.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/missouri#src-q5-idsa-program"
          },
          {
            "id": "q5-glba-ftc-30day",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "GLBA Safeguards Rule (FTC breach notice)",
            "citation": "16 C.F.R. § 314.4(j)(1).",
            "url": "https://www.law.cornell.edu/cfr/text/16/314.4",
            "deepLink": "https://www.law.cornell.edu/cfr/text/16/314.4#:~:text=Upon%20discovery%20of%20a%20notification,after%20discovery%20of%20the%20event.",
            "proposition": "The federal Safeguards Rule gives a financial institution up to 30 days after discovery to notify the FTC of a notification event involving at least 500 consumers — the federal benchmark against which Missouri's four-business-day insurance clock is far shorter.",
            "verbatimQuote": "Upon discovery of a notification event as described in paragraph (j)(2) of this section, if the notification event involves the information of at least 500 consumers, you must notify the Federal Trade Commission as soon as possible, and no later than 30 days after discovery of the event.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/missouri#src-q5-glba-ftc-30day"
          },
          {
            "id": "q5-breach-timing",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Mo. Rev. Stat. § 407.1500",
            "citation": "Mo. Rev. Stat. § 407.1500.2(1).",
            "url": "https://revisor.mo.gov/main/OneSection.aspx?section=407.1500",
            "proposition": "Missouri's general breach statute requires consumer notice without unreasonable delay rather than on a fixed-day clock.",
            "verbatimQuote": "The disclosure notification shall be: (a) Made without unreasonable delay;",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/missouri#src-q5-breach-timing"
          },
          {
            "id": "q5-idsa-vendor-clock",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Mo. Rev. Stat. § 375.1410",
            "citation": "Mo. Rev. Stat. § 375.1410.4(2).",
            "url": "https://revisor.mo.gov/main/OneSection.aspx?section=375.1410",
            "proposition": "For a cybersecurity event in a third-party service provider's system, the licensee's notification deadlines begin the day after the provider notifies it or the licensee has actual knowledge, whichever is sooner.",
            "verbatimQuote": "The computation of a licensee's deadlines shall begin on the day after the third-party service provider notifies the licensee of the cybersecurity event or the licensee otherwise has actual knowledge of the cybersecurity event, whichever is sooner.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/missouri#src-q5-idsa-vendor-clock"
          },
          {
            "id": "q5-idsa-consumer-notice",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Mo. Rev. Stat. § 375.1410",
            "citation": "Mo. Rev. Stat. § 375.1410.3.",
            "url": "https://revisor.mo.gov/main/OneSection.aspx?section=375.1410",
            "proposition": "A licensee that must notify the director must also comply with the general breach statute, § 407.1500, and provide the director a copy of the consumer notice.",
            "verbatimQuote": "The licensee shall comply with section 407.1500, as applicable, and provide a copy of the notice sent to consumers under that section to the director when a licensee is required to notify the director under subsection 1 of section 375.1410.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/missouri#src-q5-idsa-consumer-notice"
          },
          {
            "id": "q5-idsa-irp",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Mo. Rev. Stat. § 375.1405",
            "citation": "Mo. Rev. Stat. § 375.1405.8.",
            "url": "https://revisor.mo.gov/main/OneSection.aspx?section=375.1405",
            "proposition": "Each licensee's information security program must include a written incident response plan designed to promptly respond to and recover from cybersecurity events.",
            "verbatimQuote": "As part of its information security program, each licensee shall establish a written incident response plan designed to promptly respond to, and recover from, any cybersecurity event that compromises the confidentiality, integrity, or availability of nonpublic information in its possession, the licensee's information systems, or the continuing functionality of any aspect of the licensee's business or operations.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/missouri#src-q5-idsa-irp"
          },
          {
            "id": "q5-idsa-cert",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Mo. Rev. Stat. § 375.1405",
            "citation": "Mo. Rev. Stat. § 375.1405.9.",
            "url": "https://revisor.mo.gov/main/OneSection.aspx?section=375.1405",
            "proposition": "Each Missouri-domiciled insurer must certify its compliance with the information-security-program requirements to the director annually by April 15.",
            "verbatimQuote": "Annually by April fifteenth, each insurer domiciled in this state shall submit to the director a written statement certifying that the insurer is in compliance with the requirements set forth in this section.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/missouri#src-q5-idsa-cert"
          },
          {
            "id": "q5-idsa-penalty",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Mo. Rev. Stat. § 375.1420",
            "citation": "Mo. Rev. Stat. § 375.1420.",
            "url": "https://revisor.mo.gov/main/OneSection.aspx?section=375.1420",
            "proposition": "A licensee that violates the Insurance Data Security Act may be subject to the penalties provided by the insurance code's enforcement sections.",
            "verbatimQuote": "In the case of a violation of sections 375.1400 to 375.1427, a licensee may be subject to penalties as provided by law, including sections 374.046, 374.048, and 374.049.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/missouri#src-q5-idsa-penalty"
          }
        ]
      },
      {
        "slug": "consumer-lawsuit",
        "label": "Can a consumer sue your business in Missouri over privacy?",
        "heading": "Can a consumer sue your business in Missouri over privacy?",
        "answerText": "Not under the breach statute — the Attorney General has exclusive authority to sue for a willful and knowing violation — and not under the Insurance Data Security Act, which expressly creates no private cause of action. The real private-suit exposure is the MMPA: any person who purchases or leases merchandise primarily for personal, family, or household purposes and suffers an ascertainable loss of money or property from an unlawful practice may bring a private civil action for actual damages. Courts may also award punitive damages, attorney's fees to the prevailing party, and equitable relief.",
        "sources": [
          {
            "id": "q6-breach-ag-exclusive",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Mo. Rev. Stat. § 407.1500",
            "citation": "Mo. Rev. Stat. § 407.1500.4.",
            "url": "https://revisor.mo.gov/main/OneSection.aspx?section=407.1500",
            "proposition": "The Attorney General has exclusive authority to bring an action under the breach statute, so it provides consumers no private right of action.",
            "verbatimQuote": "The attorney general shall have exclusive authority to bring an action to obtain actual damages for a willful and knowing violation of this section and may seek a civil penalty not to exceed one hundred fifty thousand dollars per breach of the security of the system or series of breaches of a similar nature that are discovered in a single investigation.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/missouri#src-q6-breach-ag-exclusive"
          },
          {
            "id": "q6-idsa-no-pra",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Mo. Rev. Stat. § 375.1400",
            "citation": "Mo. Rev. Stat. § 375.1400.3.",
            "url": "https://revisor.mo.gov/main/OneSection.aspx?section=375.1400",
            "proposition": "The Insurance Data Security Act creates no private cause of action, though it also does not curtail causes of action that exist independently of it.",
            "verbatimQuote": "Sections 375.1400 to 375.1427 shall not be construed to create or imply a private cause of action for violation of their provisions, nor shall such sections be construed to curtail a private cause of action that would otherwise exist in the absence of sections 375.1400 to 375.1427.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/missouri#src-q6-idsa-no-pra"
          },
          {
            "id": "q6-mmpa-pra",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Mo. Rev. Stat. § 407.025",
            "citation": "Mo. Rev. Stat. § 407.025.1(1).",
            "url": "https://revisor.mo.gov/main/OneSection.aspx?section=407.025",
            "proposition": "A person who purchases or leases merchandise primarily for personal, family, or household purposes and suffers an ascertainable loss from an unlawful practice may bring a private civil action for actual damages.",
            "verbatimQuote": "Any person who purchases or leases merchandise primarily for personal, family or household purposes and thereby suffers an ascertainable loss of money or property, real or personal, as a result of the use or employment by another person of a method, act or practice declared unlawful by section 407.020, may bring a private civil action in either the circuit court of the county in which the seller or lessor resides or in which the transaction complained of took place, to recover actual damages.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/missouri#src-q6-mmpa-pra"
          },
          {
            "id": "q6-mmpa-elements",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Mo. Rev. Stat. § 407.025",
            "citation": "Mo. Rev. Stat. § 407.025.1(2).",
            "url": "https://revisor.mo.gov/main/OneSection.aspx?section=407.025",
            "proposition": "An MMPA damages plaintiff must establish reasonable-consumer conduct, that the unlawful practice would cause a reasonable person to enter the transaction, and individual damages proved with sufficiently definitive and objective evidence.",
            "verbatimQuote": "A person seeking to recover damages shall establish: (a) That the person acted as a reasonable consumer would in light of all circumstances; (b) That the method, act, or practice declared unlawful by section 407.020 would cause a reasonable person to enter into the transaction that resulted in damages; and (c) Individual damages with sufficiently definitive and objective evidence to allow the loss to be calculated with a reasonable degree of certainty.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/missouri#src-q6-mmpa-elements"
          },
          {
            "id": "q6-mmpa-sb591-date",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Mo. Rev. Stat. § 407.025 (revisor's applicability note)",
            "citation": "Mo. Rev. Stat. § 407.025 (revisor's note; A.L. 2020 S.B. 591).",
            "url": "https://revisor.mo.gov/main/OneSection.aspx?section=407.025",
            "proposition": "The 2020 S.B. 591 changes to § 407.025 apply to cases filed after August 28, 2020.",
            "verbatimQuote": "Applicability of statute changes for cases filed after August 28, 2020, 510.262",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/missouri#src-q6-mmpa-sb591-date"
          },
          {
            "id": "q6-mmpa-remedies",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Mo. Rev. Stat. § 407.025",
            "citation": "Mo. Rev. Stat. § 407.025.2.",
            "url": "https://revisor.mo.gov/main/OneSection.aspx?section=407.025",
            "proposition": "In an MMPA private action the court may, in its discretion, award punitive damages, prevailing-party attorney's fees, and equitable relief.",
            "verbatimQuote": "The court may, in its discretion: (1) Award punitive damages; (2) Award to the prevailing party attorney's fees, based on the amount of time reasonably expended; and (3) Provide such equitable relief as it deems necessary or proper to protect the prevailing party from the methods, acts, or practices declared unlawful by section 407.020.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/missouri#src-q6-mmpa-remedies"
          },
          {
            "id": "q6-mmpa-class",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Mo. Rev. Stat. § 407.025",
            "citation": "Mo. Rev. Stat. § 407.025.5.",
            "url": "https://revisor.mo.gov/main/OneSection.aspx?section=407.025",
            "proposition": "The MMPA authorizes class actions where an unlawful practice has caused similar injury to numerous other persons.",
            "verbatimQuote": "Persons entitled to bring an action pursuant to subsection 1 of this section may, if the unlawful method, act or practice has caused similar injury to numerous other persons, institute an action as representative or representatives of a class against one or more defendants as representatives of a class, and the petition shall allege such facts as will show that these persons or the named defendants specifically named and served with process have been fairly chosen and adequately and fairly represent the whole class, to recover damages as provided for in subsection 1 of this section.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/missouri#src-q6-mmpa-class"
          },
          {
            "id": "q6-mmpa-exemption",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Mo. Rev. Stat. § 407.020",
            "citation": "Mo. Rev. Stat. § 407.020.2(2).",
            "url": "https://revisor.mo.gov/main/OneSection.aspx?section=407.020",
            "proposition": "The MMPA does not apply to entities within the listed Missouri-regulated insurance, credit-union, and finance chapters unless those regulators authorize the Attorney General to act or a statute gives the powers to the Attorney General or a private citizen.",
            "verbatimQuote": "Any institution, company, or entity that is subject to chartering, licensing, or regulation by the director of the department of commerce and insurance under chapter 354 or chapters 374 to 385, the director of the division of credit unions under chapter 370, or director of the division of finance under chapters 361 to 369, or chapter 371, unless such directors specifically authorize the attorney general to implement the powers of this chapter or such powers are provided to either the attorney general or a private citizen by statute",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/missouri#src-q6-mmpa-exemption"
          }
        ]
      }
    ]
  }
}
