AN ACT TO CREATE THE "MISSISSIPPI CONSUMER DATA PRIVACY ACT"; TO AUTHORIZE CONSUMERS TO REQUEST THAT BUSINESSES DISCLOSE CERTAIN INFORMATION; TO AUTHORIZE CONSUMERS TO REQUEST THAT BUSINESSES DELETE PERSONAL INFORMATION COLLECTED BY BUSINESSES; TO REQUIRE BUSINESSES TO DISCLOSE CERTAIN INFORMATION TO CONSUMERS, TO INFORM CONSUMERS OF THEIR RIGHT TO REQUEST THAT PERSONAL INFORMATION BE DELETED, AND TO DELETE PERSONAL INFORMATION COLLECTED ABOUT CONSUMERS UPON REQUEST; TO AUTHORIZE CONSUMERS TO INSTRUCT BUSINESSES TO NOT SELL THE CONSUMERS' PERSONAL INFORMATION; TO AUTHORIZE CONSUMERS TO BRING CIVIL ACTIONS AGAINST BUSINESSES THAT VIOLATE THIS ACT; TO AUTHORIZE THE ATTORNEY GENERAL TO BRING CIVIL ACTIONS AGAINST BUSINESSES THAT VIOLATE THIS ACT; TO REQUIRE THE ATTORNEY GENERAL TO ADOPT REGULATIONS TO FURTHER THE PURPOSES OF THIS ACT; AND FOR RELATED PURPOSES.
SB 2015 would create the Mississippi Consumer Data Privacy Act, establishing a statewide consumer privacy framework for certain for-profit businesses operating in Mississippi. The bill gives consumers the right to know what personal information a business collects, where it comes from, whether it is sold or disclosed, and to whom; to request deletion of personal information; and to direct businesses not to sell their personal information. It also requires businesses to provide accessible notice of these rights, including a “Do Not Sell My Personal Information” link on their websites when applicable, and to respond to verified consumer requests within specified timeframes.
The bill applies to businesses meeting defined thresholds, including those with more than $10 million in annual gross revenue, those handling the personal information of at least 50,000 consumers/households/devices, or those deriving at least half of revenue from selling personal information. It defines personal information broadly to include identifiers, browsing and search history, geolocation data, biometric data, education and employment information, and inferences drawn from such data, while excluding publicly available and deidentified or aggregate information. The bill also includes special protections for minors under 16, requiring affirmative authorization for sale of their data, and limits on third-party resale of consumer data without notice and opt-out rights.
If enacted, the bill would add a new chapter of Mississippi privacy law governing the collection, disclosure, deletion, and sale of consumer personal information by covered businesses. It would impose affirmative compliance duties on businesses, create consumer enforcement rights, authorize civil actions by consumers and the Attorney General, and allow statutory damages and civil penalties for violations. The Attorney General would also be required to adopt regulations and could issue guidance to businesses and third parties. The act would preempt local ordinances and regulations on the collection and sale of consumer personal information, making it a statewide standard effective July 1, 2026.
No committee transcripts or recorded votes were provided, so there is no direct evidence of debate, amendment activity, or formal support/opposition in the available record. Based on the bill text alone, the measure is framed as a consumer-protection and privacy-rights bill intended to address identity theft, misuse of personal data, and lack of consumer control over data practices. Its structure suggests a policy approach similar to other modern consumer privacy laws, with both disclosure obligations and enforcement mechanisms.
The main points of potential contention are the scope of covered businesses, the breadth of the definition of personal information, and the compliance burden created by deletion, disclosure, opt-out, and website notice requirements. Businesses may also object to the private right of action, statutory damages, and Attorney General penalties, as well as the preemption of local privacy rules. Additional likely issues include the treatment of minors’ data, the limits and exceptions to deletion rights, and whether the bill’s exemptions for internal use, legal compliance, research, and deidentified data are sufficiently broad or narrow.