Massachusetts Information Security Regulations Take Effect on March 1, 2010
Time 2 Minute Read

After several delays and revisions, the Massachusetts information security regulations, entitled “Standards for the Protection of Personal Information of Residents of the Commonwealth,” will take effect on March 1, 2010. The regulations apply to entities that own or license personal information about Massachusetts residents. “Personal information” is defined as a combination of a resident’s first and last name and Social Security number, driver’s license or state ID number, or financial account number or payment card number that permits access to the individual’s financial account.

The regulations require entities to develop, implement and maintain a written, risk-based information security program that takes into account the entity’s size, nature of its business, types of records it maintains and the risk of identity theft posed by the entity’s operations. Also set out in the regulations are numerous administrative, technical and physical safeguards that the required information security program must include.

Finally, the regulations require covered entities to take steps to select and retain service providers that are capable of appropriately safeguarding personal information. Covered entities must contractually require their service providers to safeguard personal information in accordance with the Massachusetts regulations and applicable federal requirements; provided, however, that  service provider contracts entered into no later than March 1, 2010, are exempt from complying with this requirement until March 1, 2012.

To read more about compliance with the new regulations, please see our previous blog posts.

You May Also Be Interested In

Time 2 Minute Read

In 2025, four states—California, Massachusetts, New York, and Washington—proposed fashion accountability bills. These bills would require high-earning entities in the fashion industry to conduct extensive supply chain due diligence, and to monitor and report greenhouse gas (GHG) emissions, water use, and chemical management.

Time 5 Minute Read

Connecticut enacted SB 1295 in June, which added another round of amendments to the Connecticut Data Privacy Act. While most of the changes will take effect on July 1, 2026, impact assessment requirements will apply to processing activities created or generated on or after August 1, 2026.

Time 8 Minute Read

On April 22, 2025, the Federal Trade Commission published in the Federal Register final amendments to the Children’s Online Privacy Protection Act Rule, which will go into effect 60 days from publication, on or about June 21, 2025, with a compliance deadline of April 22, 2026.

Time 2 Minute Read

As part of the California Privacy Protection Agency’s investigative sweep of data broker registration compliance under California’s Delete Act, the CPPA recently announced an enforcement action against a Florida-based data broker and a settlement with a California-based data broker for failure to register as a data broker on the California Data Broker Registry, as required under the Delete Act.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page