Massachusetts Attorney General Reaches $110,000 Data Breach Settlement with Boston Restaurant Group
Time 2 Minute Read

On March 28, 2011, the Briar Group, LLC, owner and operator of several Boston-area bars and restaurants, reached a settlement with Massachusetts Attorney General Martha Coakley regarding the breach of “tens of thousands” of consumers’ payment card information.  The settlement resolves a lawsuit filed in Massachusetts Superior Court alleging that in April 2009 hackers gained access to the Briar Group’s computer systems and misappropriated customer data by installing malcode which was not removed by the company until December of that year.  The complaint further alleged that the Briar Group’s lax data protection practices, such as allowing employees to share computer passwords and failing to secure network wireless connections, put customers’ personal information at risk.

The Superior Court judgment requires the Briar Group to (1) pay $110,000 in civil penalties to the Commonwealth of Massachusetts, (2) comply with Massachusetts data security regulations, (3) comply with the Payment Card Industry Data Security Standards, and (4) establish and maintain an enhanced network security system.  Specifically, although the Massachusetts information security regulations were not yet in effect at the time of the breach, the settlement uses the regulations’ standards, requiring all Briar Group restaurants to develop a system to manage passwords and to implement, maintain and adhere to a written information security program.

In addressing the settlement, Attorney General Coakley emphasized that “[w]hen consumers use their credit and debit cards at Massachusetts establishments, they have an expectation that their personal information will be properly protected.”  Attorney General Coakley also stressed that her office “will continue to take action against companies that fail to implement basic security measures on their computer systems to protect the sensitive information entrusted to them by consumers.”

You May Also Be Interested In

Time 3 Minute Read

The Connecticut Attorney General recently issued a legal memorandum regarding the application of existing Connecticut laws, such as the Connecticut Data Privacy Act, to the use of artificial intelligence.

Time 3 Minute Read

On March 20, 2026, Oklahoma Governor Kevin Stitt signed SB 546 into law, enacting the Oklahoma Consumer Data Privacy Act, which will take effect on January 1, 2027.

Time 2 Minute Read

On February 5, 2026, Alabama Governor Kay Ivey signed Alabama House Bill 161, the App Store Accountability Act, establishing age categorization, age verification and parental consent requirements for mobile application marketplace providers operating in Alabama, effective January 2027.

Time 2 Minute Read

On March 5, 2026, the California Privacy Protection Agency announced that the agency had reached a settlement with Ford Motor Company resolving an enforcement action against the company that alleged noncompliance with the California Consumer Privacy Act’s opt-out of sale/sharing rights.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page