SB 2500 would create the Mississippi Consumer Data Protection Act, a comprehensive state privacy law governing how certain businesses collect, use, share, and secure personal data of Mississippi residents. The bill applies to businesses operating in Mississippi or targeting Mississippi consumers that process data for at least 100,000 consumers in a year, or at least 25,000 consumers if more than half of gross revenue comes from selling personal data. It establishes consumer rights to confirm processing, access data, delete data, obtain a portable copy of data, and opt out of the sale of personal data. It also requires controllers to provide privacy notices, offer a clear method for submitting requests, respond within set deadlines, and create an appeal process for denied requests.
The bill imposes security and governance obligations on data controllers and processors, including reasonable administrative, technical, and physical safeguards, limits on processing sensitive data, and contractual requirements for processors. It includes broad exemptions for state and local government, financial institutions, HIPAA-covered entities, nonprofits, higher education institutions, and numerous categories of health, research, employment, and other regulated data. It also preempts local laws on personal data processing and bars private lawsuits, placing enforcement exclusively with the Mississippi Attorney General, who may seek injunctions and civil penalties of up to $7,500 per violation after a 90-day cure notice.
The bill’s overall policy direction is consumer-protection oriented, with a strong emphasis on transparency, user control, and data security. Because there were no committee transcripts or recorded votes provided, there is no documented debate or formal voting history to indicate support or opposition in the available materials. The structure of the bill suggests it is modeled on modern state privacy statutes and is intended to create a uniform statewide framework for data privacy and compliance.
Notable points of contention likely center on the scope of exemptions, the threshold for covered businesses, and the enforcement model. Businesses may view the compliance, notice, and request-response obligations as burdensome, while consumer advocates may focus on the absence of a private right of action and the broad carve-outs for health, financial, research, and employment-related data. The bill also preserves several operational exceptions for fraud prevention, legal compliance, research, and internal business uses, which may be seen as necessary by industry but potentially limiting to consumer rights.
SB 2500 would add a new chapter to Mississippi law establishing statewide privacy requirements for covered data controllers and processors. It would create enforceable consumer rights, impose privacy notice and data security duties, regulate the processing of sensitive data, require processor contracts, and authorize the Attorney General to enforce the act exclusively. The bill would also preempt local government rules on personal data processing and leave existing federal privacy regimes such as HIPAA, GLBA, FCRA, COPPA, and FERPA largely intact through express exemptions.
Based on the bill text alone, the measure appears generally pro-consumer and pro-privacy, aiming to give residents more control over personal data while standardizing business obligations. No committee discussion or vote history was provided, so there is no recorded evidence of formal support, opposition, or amendments in the available materials. The absence of debate records means the public sentiment cannot be measured directly, but the bill’s design suggests an attempt to balance consumer rights with business and regulatory carve-outs.
The main points of contention are likely to be the breadth of exemptions, the business-size thresholds that determine coverage, and the decision to vest exclusive enforcement authority in the Attorney General rather than allowing private lawsuits. Industry stakeholders may object to compliance costs, request-handling deadlines, and restrictions on sensitive-data processing, while privacy advocates may argue that the cure period, exemptions, and lack of a private right of action weaken enforcement. Health care, financial services, education, nonprofit, and research entities are especially likely to support the exemptions that remove much of their data processing from the bill’s reach.