Compliance Deadline Extended for Massachusetts Data Security Regulations
Time 1 Minute Read

Massachusetts recently announced that it is extending the deadline for compliance with new state data security regulations. In consideration of the current economic climate, Massachusetts has extended its original compliance deadline of January 1, 2009. The new compliance deadline will be phased in. By May 1, 2009, companies that are subject to the regulations must generally comply with the new standards and must contractually ensure the compliance of their third-party service providers. In addition, by May 1, 2009, covered businesses must encrypt laptops containing personal information. By January 1, 2010, companies are required to have a written certification of compliance from their third-party service providers and must encrypt other company portable devices, such as memory sticks and PDAs.

Massachusetts’ new May 1, 2009, compliance deadline coincides with the updated implementation deadline for the Federal Trade Commission’s Red Flags Rule. The Red Flags Rule contains provisions requiring certain financial institutions and creditors to put in place security measures aimed at detecting and preventing identity theft. Entities that are subject to both the Red Flags Rule and Massachusetts’ new regulations may be able to address the implementation requirements of both during the same program development process.

 

You May Also Be Interested In

Time 2 Minute Read

In 2025, four states—California, Massachusetts, New York, and Washington—proposed fashion accountability bills. These bills would require high-earning entities in the fashion industry to conduct extensive supply chain due diligence, and to monitor and report greenhouse gas (GHG) emissions, water use, and chemical management.

Time 2 Minute Read

The Massachusetts Attorney General released internal TikTok documents last week as part of an unsealed complaint alleging that the company designed its platform to maximize children’s engagement while downplaying associated risks.

Time 2 Minute Read

The Supreme Judicial Court of Massachusetts, the state’s highest appellate court, recently held that website operators’ use of third-party tracking software, including Meta Pixel and Google Analytics, is not prohibited under the state’s Wiretap Act.

Time 7 Minute Read

On September 27, 2024, the United States Court of Appeals for the First Circuit (the “First Circuit”) entered judgment in favor of 7-Eleven, Inc. (“7-Eleven”) in Patel v. 7-Eleven, Inc., putting to rest a class action lawsuit 7-Eleven has been defending for more than seven years regarding allegations that its franchisees were actually employees of 7-Eleven, based on the application of the Massachusetts independent contractor statute.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page