Mississippi has had a data breach notification law since July 1, 2011, and it rarely comes up when we sit down with small business owners in Tupelo. Miss. Code § 75-24-29 applies to any person who conducts business in Mississippi and, in the ordinary course of business, owns, licenses, or maintains personal information of a Mississippi resident. The text sets no employee count and no revenue floor. If that information is breached, the business has to tell the affected people, without unreasonable delay.
That reaches further than people expect. It also reaches less far than the sales pitch for cyber coverage usually suggests. Both halves are worth knowing.
What counts as personal information
The statute defines it narrowly. It means a person’s first name or first initial and last name, combined with at least one of these:
- a Social Security number
- a driver’s license, state ID, or tribal ID number
- a financial account, credit, or debit card number, together with any security code, access code, or password needed to get into the account
Information lawfully available to the public from government records or widely distributed media doesn’t count.
On Main Street, that describes a lot of ordinary files. The car lot that photocopies a driver’s license before a test drive. The tax preparer. The contractor who keeps employees’ Social Security numbers for payroll. The shop whose card terminal or order system stores more than it should.
What counts as a breach, and what the notice looks like
A “breach of security” under the statute is the unauthorized acquisition of electronic files, media, databases, or computerized data containing that personal information, where the data was not secured by encryption or another method that makes it unreadable or unusable.
When a breach happens, disclosure goes to the affected individuals without unreasonable delay. The law allows time to investigate the scope, identify who was affected, and restore the system. Notice can be delayed if law enforcement asks because it would impede a criminal investigation. It can go by letter, phone, or electronically in certain cases. Substitute notice, meaning email, a conspicuous website posting, and notice to major statewide media, is allowed when direct notice would cost more than $5,000, more than 5,000 people are affected, or the business lacks contact information. A business that only maintains data for someone else has to notify the owner of that data.
There is one more piece people miss. No notice is required if, after an appropriate investigation, the business reasonably determines the breach will not likely result in harm.
The part that doesn’t flatter us
This statute is narrower than a lot of cyber insurance marketing implies. It is enforced by the Attorney General as an unfair trade practice, and the text says plainly that it creates no private right of action. Data that was encrypted falls outside its definition of a breach. So do paper files, and a customer email list with no Social Security, license, or card numbers on it. For plenty of small shops, the direct exposure under this particular law is modest.
That is not the same as saying a breach is cheap. Figuring out what happened, restoring systems, and mailing letters cost money whether or not anybody sues. Those costs exist even when the law is satisfied.
Where insurance typically sits
The Insurance Information Institute’s overview of cyber liability risks lists notification expenses alongside system recovery, liability to third parties, and regulatory fines as the costs a business can face. It also notes that some standard business policies, such as a Business Owners Policy, may respond to certain cyber incidents, like data lost to a virus or hardware failure. The fuller range of cyber risks is typically addressed by a stand-alone cyber liability policy.
In practice, policies vary a great deal here. Some business policies carry a data-related endorsement with its own sublimit. Some carry nothing on it. Some exclude it outright. The place to look is the endorsement schedule on the declarations page, for words like “data compromise,” “cyber,” or “electronic data,” and the dollar figure beside them. If those words aren’t there, the policy is the thing that answers what happens next, not this article.
If you’d like a second set of eyes on what your business policy says about data, come by the Tupelo office, see our business insurance page, or call or text 662-454-7831.
This article is general information about how coverage typically works, not advice about your specific situation. Your policy is the contract, and it’s the only thing that says what you have. If you’d like someone to read it with you, that’s what we’re here for.