Learn more about the latest security and privacy threats
Back

The Missouri age verification law now in force: section 407.3405 bans the verifier from keeping anything

Michelangelo Frigo Michelangelo Frigo (Co-Founder at Zyphe) Published August 31, 2026 Reviewed by Charlene Wang
Editorial illustration for the article "The Missouri age verification law now in force: section 407.3405 bans the verifier from keeping anything".

Missouri's age verification law took effect on 28 August 2026. Section 407.3405 makes operators use a third party and bars that verifier from keeping data.

Table of contents

The Missouri age verification law took effect on 28 August 2026, and section 407.3405 goes further than the Texas template it copies: it forces covered sites to outsource the age check to a third party, then forbids that third party from retaining any identifying information. Penalties run to 10,000 dollars a day.

  • Section 407.3405 RSMo took effect on 28 August 2026, enacted by HB 1839 and signed on 9 July 2026.
  • Sites where more than one-third of the material is sexual material harmful to minors must use a third party to verify that visitors are eighteen or older.
  • The statute bars that third party from retaining any identifying information, but writes the 10,000 dollar retention penalty against a commercial entity, leaving vendor liability open.
  • Penalties run to 10,000 dollars per day, 10,000 dollars per retention instance, and up to 250,000 dollars more if a minor got through.
  • An attorney general rule has covered similar conduct under a different definition since 30 November 2025, so the Missouri age verification law now overlaps a regime already in force.

What does the Missouri age verification law require?

Section 407.3405 RSMo reaches any commercial entity that knowingly and intentionally publishes or distributes material on an internet website, including a social media platform, more than one-third of which is sexual material harmful to minors. Those operators must use a third party to verify that visitors are eighteen or older.

Two design choices set this text apart from its Texas template. The first sits in subsection 2: the operator "shall use a third party" to perform the check, so an in-house age gate does not satisfy the statute. The second sits in subsection 3, which says a third party performing the verification "shall not retain any identifying information of the individual." That is the whole clause: no carve-out, no retention window, no exception for records another law requires.

Accepted methods under the Missouri age verification law are narrow. A visitor either provides digital identification, meaning identity information held on a digital network a commercial entity can access, or clears a commercial system built on government-issued identification or on a commercially reasonable method relying on transactional data. The statute defines transactional data to include records from mortgage, education and employment entities.

ItemDetail
InstrumentSection 407.3405, RSMo
Enacting billHCS HBs 1839, 2921 and 3015 (HB 1839)
Truly agreed and finally passed13 May 2026, House vote 112 to 25
Approved by the Governor9 July 2026
In force from28 August 2026
Coverage thresholdMore than one-third of site material
Who performs the checkA third party, mandatory
Retention ruleThird party shall not retain identifying information
EnforcementMissouri Attorney General, by court action

Article III, section 29 of the Missouri Constitution delays any law without an emergency clause until ninety days after the session adjourns, and this bill carried none.

How does it differ from the Texas model and the attorney general's rule?

Section 407.3405 copies the Texas architecture, then changes two things that matter operationally. Texas chapter 129B, enacted with a 1 September 2023 effective date, lets the commercial entity verify age itself or use a third party, and bars either from retaining identifying information. Missouri removes the first option and narrows the second. Missouri's own attorney general rule, in force since November 2025, is broader in scope and softer on penalties. The Supreme Court upheld the Texas age-verification requirement in Free Speech Coalition v. Paxton.

ProvisionSection 407.3405 (Missouri)15 CSR 60-18 (Missouri AG rule)Chapter 129B (Texas)
In force since28 August 202630 November 20251 September 2023
What is coveredWebsite, including social mediaWebsite, application, or content segmentWebsite, including social media
Coverage measurementNot defined33% or more of public dataNot defined
Third party mandatoryYesNoNo
Alternative method allowedNoYes, if equally effectiveNo
Who may not retainThe third partyThe entity and any third partyThe entity or the third party
Exception where law requires retentionNone statedYes, law or court orderNone stated
Express security dutyNone statedYes, commercially reasonable methodsNone stated
Daily penalty10,000 dollars per dayCapped at 10,000 dollars in a single dayNot more than 10,000 dollars per day
Retention penalty10,000 dollars per instanceCounted as violationsNot more than 10,000 dollars per instance
Minor-access penaltyUp to 250,000 dollarsNoneNot more than 250,000 dollars

Texas caps its per-day and per-instance figures at "not more than" 10,000 dollars, and section 129B.006(c) tells a court to scale the amount by the seriousness of the violation, the history of previous violations and the amount needed to deter. Missouri states both figures flat, reserves "not more than" only for the minor-access uplift, and gives no scaling factors.

Rule 15 CSR 60-18, filed on 10 April 2025 and effective 30 November 2025, treats a non-compliant site as an unfair practice under the Missouri Merchandising Practices Act. That rule already banned retention, but it bound both the operator and the verifier, allowed retention where another law or a court order required it, and imposed a duty to secure whatever was collected. The Missouri age verification law carries none of those three provisions.

What changes for your compliance obligations?

For a regulated firm the Missouri age verification law is not an anti-money laundering rule, yet it lands on the identity stack that anti-money laundering work runs through. Four duties change shape: how you choose a vendor, how long you keep identity records, how you evidence compliance, and what your processing agreements say about deletion.

Vendor selection stops being a build-or-buy decision, because an in-house age gate fails subsection 2. Firms that treat identity verification as a core internal capability now need contracted third party age verification for this flow, with the contract naming the retention prohibition.

Retention duties point in opposite directions on shared infrastructure. A bank's Customer Identification Program must keep the identifying information it collects for five years after the account is closed under 31 CFR 1020.220(a)(3). Section 407.3405 forbids retention on the age-check path. A verifier serving both flows has to keep them separate, because one identity store cannot satisfy both commands.

Evidence of compliance has to be built without the records that would normally prove it. The attorney general can seek 10,000 dollars for each day of non-compliant operation, so an operator will want to show every session was checked, yet cannot do so by keeping identifying information. The answer is non-identifying evidence: counted verifications, timestamps, method codes and vendor attestations, in an audit trail carrying no personally identifiable information.

Data processing agreements need a deletion clause mirroring the statute, not a generic retention schedule. The exposure is asymmetric: subsection 3 puts the duty on the third party, while the per-instance penalty in subsection 6 is written against the commercial entity. Contract for proof that the verifier holds nothing.

What is still uncertain?

Section 407.3405 imposes the no-retention duty on one party and the penalty on another. Subsection 3 binds the third party. Subsection 6 then sets a penalty "when a commercial entity retains identifying information in violation of this section." The statute's definition of commercial entity ends with "or other legally recognized business entity", with no carve-out for a vendor performing the check.

So an attorney general could read the subsection 6 penalty as reaching the vendor, the publisher, or both. Until a court says otherwise, an operator cannot tell whether its vendor's mistake is its own liability, an odd position when the outsourcing was ordered by statute.

The statute also never says what the one-third is measured against. The attorney general's rule defines a substantial portion as 33 percent or more of the total data publicly available on a website. Section 407.3405 carries no equivalent measurement, and the two tests do not align: a site at exactly one-third is inside the rule and arguably outside the statute. An operator scoping its own compliance has no statutory denominator.

Section 407.3405 defines nine terms. "Identifying information", the thing a verifier may not keep, is not one of them. Nothing in the text says whether a hashed token, a pass or fail flag tied to a session, or an access log counts.

A missing exception is the next gap. The attorney general's rule permits retention where another law or a court order requires it. The statute does not. A verifier under a litigation hold, or one carrying federal record-keeping duties, must choose which command to break.

The two regimes overlap. The rule reaches material "pornographic for minors" and the statute reaches "sexual material harmful to minors", two different tests, enforced one as an unfair practice and one as a statutory violation. The rule caps counted violations at 10,000 dollars in a single day, and that cap does not limit the statute, so one non-compliant day can generate exposure under both.

Finally, the market response may not be verification at all. When the rule took effect in November 2025, Pornhub blocked access in Missouri rather than comply. "Pornhub's decision proves exactly why this rule is necessary," said Attorney General Catherine Hanaway. Exit is likely to push traffic to sites that ignore the rule and to virtual private networks, a poorer outcome for minors than a working check.

Why does a no-retention rule change the identity architecture?

A no-retention rule is only as strong as the system underneath it. Most verification vendors collect a document image, run a check and hold the result, because that is how they support disputes, re-checks and audit obligations. Telling such an architecture to keep nothing is a promise about deletion, not a property of the design.

The distinction matters because the alternative to holding identity data is not holding it more carefully. Every retained record is a target, and a data breach at an age-verification vendor exposes what the statute meant to keep out of circulation: government identifiers tied to a browsing context. Missouri's transactional-data method arguably widens that exposure, routing the visitor through a data broker lookup instead of one document check.

The architecture that satisfies subsection 3 by construction is one where the verifier never assembles a complete record. That is the question regulated firms already face in KYC onboarding, and it is why storing less is the load-bearing design decision. When no single party holds a complete record, "we retained nothing" describes the system rather than a deletion job that may or may not have run.

How should compliance teams respond?

The statute is enforceable now, and the per-day penalty accrues while a team is still deciding whether it is in scope. Work through the six steps below in order.

  1. Scope the estate. Decide whether any property crosses the one-third threshold in Missouri, and record the denominator you used, because the statute does not supply one.
  2. Confirm a third party performs the check. An in-house gate does not comply, however accurate.
  3. Amend the vendor agreement so it repeats the statutory language on retention, and require evidence that the verifier holds nothing, not a deletion commitment.
  4. Separate any pipeline serving both age checks and Customer Identification Program checks, since one forbids retention and the other compels it for five years.
  5. Build a non-identifying audit trail of verification counts and method codes.
  6. Track the litigation, because who pays for a vendor's retention is still open.

Teams facing this in Europe should read it alongside the EU age verification trusted list, and those tracking the American position should compare the Texas app store ruling with the blocked Nebraska statute.

Zyphe was built for the constraint Missouri has now written into statute. Personal data is sharded across a decentralised network of more than 60,000 nodes under a 29-of-100 threshold scheme, the customer holds the key, and there is no master key and no central honeypot to retain. Verification runs from an NFC chip read to ICAO 9303 and eIDAS standards with two-step liveness and no image upload, and the audit trail we export carries the evidence of a check without the identity behind it. That is step 5 implemented in decentralised storage rather than in a retention policy. Book a demo.

The bottom line

The Missouri age verification law takes the Texas template and pushes it in a direction that changes engineering, not just policy. Mandating a third party removes the in-house option, and barring that third party from keeping anything turns a data-handling preference into a condition of operating. For teams running identity checks the lesson generalises well past adult content: the safest way to comply with a rule that says keep nothing is to run a system that was never able to keep it. Deletion policies are promises. Architecture is evidence.

Cited sources

Michelangelo Frigo Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.

Frequently Asked Questions

Section 407.3405 RSMo took effect on 28 August 2026. It was truly agreed and finally passed on 13 May 2026 as HCS HBs 1839, 2921 and 3015, and approved by the Governor on 9 July 2026. The date follows Article III, section 29 of the Missouri Constitution, which delays laws without an emergency clause until ninety days after the session adjourns.

It covers any commercial entity that knowingly and intentionally publishes or distributes material on an internet website, including a social media platform, more than one-third of which is sexual material harmful to minors. Bona fide news and public interest content is excluded, as are the rights of news-gathering organizations. Internet service providers, search engines and cloud providers are not liable merely for carrying content they did not create.

The statute sets a three-part test. An average person applying contemporary community standards must find that the material, taken as a whole and with respect to minors, is designed to appeal to or pander to the prurient interest. It must be patently offensive with respect to minors in what it depicts, and taken as a whole it must lack serious literary, artistic, political or scientific value for minors. All three limbs have to be met.

No. Subsection 2 requires the covered operator to use a third party to perform reasonable age-verification methods. This is the main structural difference from Texas chapter 129B, which allows the commercial entity to verify age itself. An in-house gate, however accurate, does not meet the Missouri requirement on its own.

A court may award damages, injunctive relief, costs and fees, plus civil penalties of 10,000 dollars per day of non-compliant operation, 10,000 dollars per instance of retaining identifying information, and up to an additional 250,000 dollars if one or more minors accessed the material because of the violation. The statute assigns enforcement to the attorney general and creates no private right of action of its own.

By keeping evidence about the check rather than about the person. Counted verifications, timestamps, method codes and signed attestations from the verifier show that every session was gated without storing anything that identifies a visitor. Age verification data retention is the trap here: the record that would most easily prove compliance is the record the statute forbids you to hold.

See privacy-first KYC in action

Verify identity without storing a single document. Reusable credentials, an exportable audit trail, and a 15-minute integration.

Book a demo