Missouri

Who Is Covered?

Any person that owns or licenses personal information of residents of Missouri or any person that conducts business in Missouri that owns or licenses personal information in any form of a resident of Missouri. Mo. Rev. Stat. § 407.1500(2)(1).

What Information Is Protected?

“Personal information” means an individual’s first name or first initial and last name in combination with any one or more of the following data elements that relate to the individual if any of the data elements are not encrypted, redacted, or otherwise altered by any method or technology in such a manner that the name or data elements are unreadable or unusable:

  1. Social security number;
  2. Driver’s license number or other unique identification number created or collected by a government body;
  3. Financial account number, credit card number, or debit card number in combination with any required security code, access code, or password that would permit access to an individual’s financial account;
  4. Unique electronic identifier or routing code, in combination with any required security code, access code, or password that would permit access to an individual’s financial account;
  5. Medical information; or
  6. Health insurance information. Mo. Rev. Stat. § 407.1500(1)(9).

What Is A “Breach”?

“Breach of security” or “breach” is the unauthorized access to and unauthorized acquisition of personal information maintained in computerized form by a person that compromises the security, confidentiality, or integrity of the personal information. Good faith acquisition of personal information by a person or that person’s employee or agent for a legitimate purpose of that person is not a breach of security, provided that the personal information is not used in violation of applicable law or in a manner that harms or poses an actual threat to the security, confidentiality, or integrity of the personal information. Mo. Rev. Stat. § 407.1500(1)(1).

What Triggers Notification?

Discovery or notification of a breach. Mo. Rev. Stat. § 407.1500(2)(1).

Likelihood of Harm Analysis: Notification is not required if, after an appropriate investigation by the person or after consultation with the relevant federal, state, or local agencies responsible for law enforcement, the person determines that a risk of identity theft or other fraud to any consumer is not reasonably likely to occur as a result of the breach. Such a determination shall be documented in writing and the documentation shall be maintained for five years. Mo. Rev. Stat. § 407.1500(2)(5).

How Is Notice Provided To Individuals?

Timing: Notification must be made:

  1. Without unreasonable delay;
  2. Consistent with the legitimate needs of law enforcement, as provided in this section; and
  3. Consistent with any measures necessary to determine sufficient contact information and to determine the scope of the breach and restore the reasonable integrity, security, and confidentiality of the data system. Mo. Rev. Stat. § 407.1500(2)(1).

Delivery: Notice may be by:

  1. Written notice;
  2. Electronic notice for those consumers for whom the person has a valid email address and who have agreed to receive communications electronically, if the notice provided is consistent with the provisions of 15 U.S.C. Section 7001 regarding electronic records and signatures for notices legally required to be in writing;
  3. Telephonic notice, if such contact is made directly with the affected consumers; or
  4. Substitute notice, if: a) The person demonstrates that the cost of providing notice would exceed one hundred thousand dollars; or b) The class of affected consumers to be notified exceeds one hundred fifty thousand; or c) The person does not have sufficient contact information or consent to satisfy paragraphs 1, 2 or 3 above, for only those affected consumers without sufficient contact information or consent; or d) The person is unable to identify particular affected consumers, for only those unidentifiable consumers. Mo. Rev. Stat. § 407.1500(2)(6).

Content: The notice must describe:

  1. The incident in general terms;
  2. The type of personal information that was obtained as a result of the breach of security;
  3. A telephone number that the affected consumer may call for further information and assistance, if one exists;
  4. Contact information for consumer reporting agencies;
  5. Advice that directs the affected consumer to remain vigilant by reviewing account statements and monitoring free credit reports. Mo. Rev. Stat. § 407.15009(2)(4).

Is Notice To The Government Required?

Yes. In the event a person provides notice to more than one thousand consumers at one time pursuant to this section, the person shall notify, without unreasonable delay, the attorney general’s office and all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis of the timing, distribution, and content of the notice. Mo. Rev. Stat. § 407.1500(2)(8).

Is Notice To Credit Reporting Agencies Required?

Yes. In the event a person provides notice to more than one thousand consumers at one time pursuant to this section, the person shall notify, without unreasonable delay, the attorney general’s office and all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis of the timing, distribution, and content of the notice. Mo. Rev. Stat. § 407.1500(2)(8).

Are There Security Measure Standards?

No.

What Are The Possible Consequences Of A Violation?

The attorney general shall have exclusive authority to bring an action to obtain actual damages for a willful and knowing violation of this section and may seek a civil penalty not to exceed $150,000 per breach of the security of the system or series of breaches of a similar nature that are discovered in a single investigation. Mo. Rev. Stat. § 407.1500(4).

Are There Any Exemptions/Exceptions?

A person that maintains its own notice procedures as part of an information security policy for the treatment of personal information, and whose procedures are otherwise consistent with the timing requirements of this section, is deemed to be in compliance with the notice requirements of this section if the person notifies affected consumers in accordance with its policies in the event of a breach of security of the system. Mo. Rev. Stat. § 407.1500(3)(1).

Also, a person that is regulated by state or federal law and that maintains procedures for a breach of the security of the system pursuant to the laws, rules, regulations, guidances, or guidelines established by its primary or functional state or federal regulator is deemed to be in compliance with this section if the person notifies affected consumers in accordance with the maintained procedures when a breach occurs. Mo. Rev. Stat. § 407.1500(3)(2).

Finally, a financial institution is deemed to be in compliance if it is:

  1. Subject to and in compliance with the Federal Interagency Guidance Response Programs for Unauthorized Access to Customer Information and Customer Notice, issued on March 29, 2005, by the board of governors of the Federal Reserve System, the Federal Deposit Insurance Corporation, the Office of the Comptroller of the Currency, and the Office of Thrift Supervision, and any revisions, additions, or substitutions relating to said interagency guidance; or
  2. Subject to and in compliance with the National Credit Union Administration regulations in 12 CFR Part 748; or
  3. Subject to and in compliance with the provisions of Title V of the Gramm-Leach-Bliley Financial Modernization Act. Mo. Rev. Stat. § 407.1500(3)(3).