State Breach Law
Massachusetts Data Breach Notification Law
M.G.L. c. 93H, 201 CMR 17.00 • Effective 2007-10-31
Massachusetts is one of the strictest states for data protection. If you have data on Massachusetts residents, you need a Written Information Security Program (WISP) - not just breach notification procedures. Breaches must be reported "as soon as practicable" to both affected individuals and the Attorney General.
Notification deadline: As soon as practicable and without unreasonable delay
Enforcement: Massachusetts Attorney General, Office of Consumer Affairs
Overview
Massachusetts has some of the most comprehensive data security requirements in the nation. Beyond breach notification, the 201 CMR 17.00 regulations mandate a written information security program (WISP) for any business handling Massachusetts residents' personal information.
Who Must Be Notified
- • Affected Massachusetts residents
- • Massachusetts Attorney General (always, regardless of number affected)
- • Director of Consumer Affairs and Business Regulation
Covered Data Types
Social Security number, Driver's license number, State ID number, Financial account number with access code, Credit/debit card number
Notification Requirements
- • Written notice to affected individuals
- • Include description of breach and data types involved
- • Steps taken to address breach
- • Must notify AG and Director of Consumer Affairs (specific form required)
- • Cannot include description of security measures in notification
- • Credit monitoring must be offered if SSN exposed
Is your business exposed?
Exemptions
- • Encrypted data (if key not compromised)
- • Publicly available information
- • Good faith acquisition by employee (if not misused)
Penalties
Up to $5,000 per violation under consumer protection laws. AG can seek injunctions, restitution, and penalties. Class action lawsuits possible.
If You Experience a Breach
- 1.
Create Written Information Security Program (WISP) - REQUIRED
- 2.
Designate employee to maintain WISP
- 3.
Encrypt all portable devices and transmitted data
- 4.
Implement secure user authentication protocols
- 5.
Know how to file with MA AG (form submission required)
- 6.
Train employees on security awareness annually
Official Source
https://www.mass.gov/info-details/data-breach-notificationIs your business exposed?
Check if your company data is circulating on the dark web
Free scan • No credit card required