Mississippi An Act to Require Notice of a Breach of Security (Miss. Code Ann. § 75-24-29)

Mississippi An Act to Require Notice of a Breach of Security

Miss. Code Ann. § 75-24-29

 

SUMMARY:

EFFECTIVE.  July 1, 2011

WHO DOES THIS LAW APPLY TO.  Any person or entity that conducts business in Mississippi and owns, licenses or maintains Personal Information on any resident.

WHAT IS A BREACH.  An unauthorized acquisition of unencrypted electronic files, media, databases, or computerized data containing Personal Information of a Mississippi resident. 

WHAT IS PERSONAL INFORMATION.  An individual’s first name or first initial and last name in combination with any one or more of the following data elements:

  • Social Security Number.
  • Driver’s license number, State identification card number or Tribal identification card number.
  • Account number, credit card or debit card number in combination with any required security code, access code, or password that would permit access to the individual’s financial account.

Personal Information does not include publicly available information, information that is lawfully available from Federal, State, or local government records, or widely distributed media.

WHO TO NOTIFY OF THE BREACH.  Notification of the breach must be sent to the individual(s) affected.  No notification is required if the person or business, after a reasonable investigation, determines that a breach of the security of the system will not likely result in harm to the affected individual(s). 

EXCEPTIONThis Section does not apply to the following:

  • A person or business which maintains its own notice procedures as part of a Personal Information security policy and is otherwise consistent with the timing requirements of this Section, is considered in compliance with this Section if the affected Mississippi individuals are notified by the person or business in accordance with its policies.
  • A person or business that is regulated by State or Federal law and maintains procedures for a security breach pursuant to the State or Federal laws or rules, is considered in compliance with this Section, if the affected Mississippi individuals are notified in accordance with such policies.

WHEN TO NOTIFY OF THE BREACHDisclosure shall be made to the affected individual(s) in the most expedient manner possible and without unreasonable delay consistent with measures necessary to determine the nature and scope of the breach, to identify the individual(s) affected or to restore the reasonable integrity of the data system.  Notification may be delayed if it will impede a criminal investigation or national security and is requested by law enforcement.  In that instance, notification will be made as soon as possible following clearance by law enforcement. 

HOW TO NOTIFY OF THE BREACH.  Notice may be provided by one of the following methods:

  • Written.
  • Telephonic.
  • Electronic (if it is the primary means of communication, or notice is consistent with the provisions regarding electronic records and signatures in 15 U.S.C. § 7001).
  • Substitute notice as provided below.

SUBSTITUTE NOTICE AVAILABLE.  If the person or business can demonstrate that the cost of providing notice will exceed $5,000, the affected class of persons to be notified exceeds 5,000, or the person or business has insufficient contact information, substitute notice may be used.  Substitute notice shall consist of all of the following:

  • Email notice if the person or business has an Email address for the individual(s) subject to notice.
  • Conspicuous posting of the notice on the website of the person or business if one is maintained.
  • Notification to major statewide media.

NOTICE TO THIRD-PARTIES.  If a person or business maintains computerized data that includes Personal Information that it does not own, then the person or business shall notify the owner or licensee as soon as possible following discovery of the breach.  The person or entity that conducts business in Mississippi shall provide notice to the affected individual(s). 

CONSEQUENCES FOR FAILING TO NOTIFYAny violation of this Section will constitute an unfair trade practice and will be enforced by the state Attorney General.

PRIVATE RIGHT OF ACTIONNone provided in the statute.

REQUIREMENTS OF REASONABLE SECURITY MEASURES

DATA DISPOSAL PROVISIONSNone.

LEGISLATIVE UPDATES.

H.B. 582 – Signed into law on 4/7/2010, Effective 7/1/2011.

H.B. 277 – Signed into law on 3/18/2021, Effective 7/1/2021.

 

 

CITATION:

Mississippi Code 1972 Annotated

Title 75. Regulation of Trade, Commerce and Investments (Chs. 1 — 95)

Chapter 24. Regulation of Business for Consumer Protection (§§ 75-24-1 — 75-24-359)

General Provisions (§§ 75-24-1 — 75-24-29)

§ 75-24-29. Persons conducting business in Mississippi required to provide notice of a breach of security involving personal information to all affected individuals; enforcement.

 

§ 75-24-29. Persons conducting business in Mississippi required to provide notice of a breach of security involving personal information to all affected individuals; enforcement.

(1) This section applies to any person who conducts business in this state and who, in the ordinary course of the person’s business functions, owns, licenses or maintains personal information of any resident of this state.

(2) For purposes of this section, the following terms shall have the meanings ascribed unless the context clearly requires otherwise:

(a) “Breach of security” means unauthorized acquisition of electronic files, media, databases or computerized data containing personal information of any resident of this state when access to the personal information has not been secured by encryption or by any other method or technology that renders the personal information unreadable or unusable;

(b) “Personal information” means an individual’s first name or first initial and last name in combination with any one or more of the following data elements:

(i) Social security number;

(ii) Driver’s license number, state identification card number or tribal identification card number; or

(iii) An account number or credit or debit card number in combination with any required security code, access code or password that would permit access to an individual’s financial account; “personal information” does not include publicly available information that is lawfully made available to the general public from federal, state or local government records or widely distributed media;

(iv) “Affected individual” means any individual who is a resident of this state whose personal information was, or is reasonably believed to have been, intentionally acquired by an unauthorized person through a breach of security.

(3) A person who conducts business in this state shall disclose any breach of security to all affected individuals. The disclosure shall be made without unreasonable delay, subject to the provisions of subsections (4) and (5) of this section and the completion of an investigation by the person to determine the nature and scope of the incident, to identify the affected individuals, or to restore the reasonable integrity of the data system. Notification shall not be required if, after an appropriate investigation, the person reasonably determines that the breach will not likely result in harm to the affected individuals.

(4) Any person who conducts business in this state that maintains computerized data which includes personal information that the person does not own or license shall notify the owner or licensee of the information of any breach of the security of the data as soon as practicable following its discovery, if the personal information was, or is reasonably believed to have been, acquired by an unauthorized person for fraudulent purposes.

(5) Any notification required by this section shall be delayed for a reasonable period of time if a law enforcement agency determines that the notification will impede a criminal investigation or national security and the law enforcement agency has made a request that the notification be delayed. Any such delayed notification shall be made after the law enforcement agency determines that notification will not compromise the criminal investigation or national security and so notifies the person of that determination.

(6) Any notice required by the provisions of this section may be provided by one (1) of the following methods: (a) written notice; (b) telephone notice; (c) electronic notice, if the person’s primary means of communication with the affected individuals is by electronic means or if the notice is consistent with the provisions regarding electronic records and signatures set forth in 15 USCS 7001; or (d) substitute notice, provided the person demonstrates that the cost of providing notice in accordance with paragraph (a), (b) or (c) of this subsection would exceed Five Thousand Dollars ($5,000.00), that the affected class of subject persons to be notified exceeds five thousand (5,000) individuals or the person does not have sufficient contact information. Substitute notice shall consist of the following: electronic mail notice when the person has an electronic mail address for the affected individuals; conspicuous posting of the notice on the website of the person if the person maintains one; and notification to major statewide media, including newspapers, radio and television.

(7) Any person who conducts business in this state that maintains its own security breach procedures as part of an information security policy for the treatment of personal information, and otherwise complies with the timing requirements of this section, shall be deemed to be in compliance with the security breach notification requirements of this section if the person notifies affected individuals in accordance with the person’s policies in the event of a breach of security. Any person that maintains such a security breach procedure pursuant to the rules, regulations, procedures or guidelines established by the primary or federal functional regulator, as defined in 15 USCS 6809(2), shall be deemed to be in compliance with the security breach notification requirements of this section, provided the person notifies affected individuals in accordance with the policies or the rules, regulations, procedures or guidelines established by the primary or federal functional regulator in the event of a breach of security of the system.

(8) Failure to comply with the requirements of this section shall constitute an unfair trade practice and shall be enforced by the Attorney General; however, nothing in this section may be construed to create a private right of action.

History

Laws, 2010, ch. 489, § 1, eff from and after July 1, 2011; Laws, 2021, ch. 378, § 9, eff from and after July 1, 2021.

 

Mississippi Code 1972 Annotated

Copyright © 2022 The State of Mississippi All rights reserved.

 

 

For more information, see here:  https://advance.lexis.com/documentpage/?pdmfid=1000516&crid=b973dda5-6245-4584-9f5b-35649c111375&nodeid=ABNAAWAABAAQ&nodepath=%2FROOT%2FABN%2FABNAAW%2FABNAAWAAB%2FABNAAWAABAAQ&level=4&haschildren=&populated=false&title=%C2%A7+75-24-29.+Persons+conducting+business+in+Mississippi+required+to+provide+notice+of+a+breach+of+security+involving+personal+information+to+all+affected+individuals%3B+enforcement.&config=00JABhZDIzMTViZS04NjcxLTQ1MDItOTllOS03MDg0ZTQxYzU4ZTQKAFBvZENhdGFsb2f8inKxYiqNVSihJeNKRlUp&pddocfullpath=%2Fshared%2Fdocument%2Fstatutes-legislation%2Furn%3AcontentItem%3A627R-MSW3-GXJ9-31CB-00008-00&ecomp=vg1_kkk&prid=0f77a537-652a-4c84-afd4-d4714b5d3f1a

 

These materials were obtained directly from the State Legislative websites and are posted here for your review and reference only.  No Claim to Original State Government Works.  This may not be the most recent version.  The State may have more current information.  We make no guarantees or warranties about the accuracy or completeness of this information, or the information linked to.  Please check the linked sources directly.