State Breach Law

Massachusetts Data Breach Notification Law

M.G.L. c. 93H, 201 CMR 17.00 • Effective 2007-10-31

Massachusetts is one of the strictest states for data protection. If you have data on Massachusetts residents, you need a Written Information Security Program (WISP) - not just breach notification procedures. Breaches must be reported "as soon as practicable" to both affected individuals and the Attorney General.

Notification deadline: As soon as practicable and without unreasonable delay

Enforcement: Massachusetts Attorney General, Office of Consumer Affairs

Overview

Massachusetts has some of the most comprehensive data security requirements in the nation. Beyond breach notification, the 201 CMR 17.00 regulations mandate a written information security program (WISP) for any business handling Massachusetts residents' personal information.

Who Must Be Notified

  • Affected Massachusetts residents
  • Massachusetts Attorney General (always, regardless of number affected)
  • Director of Consumer Affairs and Business Regulation

Covered Data Types

Social Security number, Driver's license number, State ID number, Financial account number with access code, Credit/debit card number

Notification Requirements

  • Written notice to affected individuals
  • Include description of breach and data types involved
  • Steps taken to address breach
  • Must notify AG and Director of Consumer Affairs (specific form required)
  • Cannot include description of security measures in notification
  • Credit monitoring must be offered if SSN exposed

Is your business exposed?

Exemptions

  • Encrypted data (if key not compromised)
  • Publicly available information
  • Good faith acquisition by employee (if not misused)

Penalties

Up to $5,000 per violation under consumer protection laws. AG can seek injunctions, restitution, and penalties. Class action lawsuits possible.

If You Experience a Breach

  1. 1.

    Create Written Information Security Program (WISP) - REQUIRED

  2. 2.

    Designate employee to maintain WISP

  3. 3.

    Encrypt all portable devices and transmitted data

  4. 4.

    Implement secure user authentication protocols

  5. 5.

    Know how to file with MA AG (form submission required)

    MA AG Data Breach Form

  6. 6.

    Train employees on security awareness annually

Official Source

https://www.mass.gov/info-details/data-breach-notification

Other State Breach Laws

New York, Texas, Florida

Is your business exposed?

Check if your company data is circulating on the dark web

Free scan • No credit card required