EnglishEspañol
Massachusetts flag

Massachusetts

Massachusetts Data Privacy Laws: Security Rules & Consumer Rights (2026)

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 26 primary sources cited on this page. How we verify our legal content

Massachusetts Data Privacy Laws: Security Rules & Consumer Rights (2026)

Frequently Asked Questions

Does Massachusetts have a comprehensive data privacy law?

No. Massachusetts does not have a comprehensive consumer data privacy law in effect as of August 2026. The Senate passed its version of the Massachusetts Data Privacy Act (S.2608, re-engrossed as S.2619) 40-0 on September 25, 2025, and the House passed its own competing version (H.5479) 146-0 on June 4-5, 2026. A conference committee has been reconciling the two bills since June 2026, and no compromise bill has reached the Governor. Until a final bill is signed into law, Massachusetts residents do not have statutory rights to access, correct, or delete their personal data. The state protects personal information through sectoral laws: 201 CMR 17.00 (data security), Chapter 93H (breach notification), Chapter 93I (records disposal), and Chapter 93A (consumer protection enforcement).

What is a WISP and who needs one in Massachusetts?

A WISP is a Written Information Security Program required by 201 CMR 17.00. Every person or business that owns or licenses personal information about a Massachusetts resident must maintain one, regardless of where the business is located. The WISP must be a written document addressing risk assessment, employee policies, third-party vendor oversight, physical access controls, and regular review and updates. The AG and OCABR inspect the WISP when a breach is reported. Not having one, or having one that fails to address the required elements, is itself a violation subject to penalties under Chapter 93A.

What are Massachusetts' data breach notification requirements?

Under Chapter 93H, a business must notify the Attorney General, the Office of Consumer Affairs and Business Regulation, and each affected Massachusetts resident as soon as practicable and without unreasonable delay after discovering a breach. In August 2025 the Attorney General alleged that Peabody Properties had delayed notification by nearly seven months and resolved the claims through a $795,000 consent judgment, which shows the enforcement risk of a slow notification rather than a deadline set by a court. If Social Security numbers were compromised, the entity must also provide 18 months of free credit monitoring. Notice to residents must describe their right to file a police report and information about credit freezes.

What are the penalties for violating Massachusetts data privacy laws?

Violations of 201 CMR 17.00 and Chapter 93H are enforced through Chapter 93A at up to $5,000 per violation. The AG can also seek injunctive relief. Private plaintiffs who prove a willful violation can recover treble damages plus attorney fees. For improper records disposal under Chapter 93I, the civil fine is up to $100 per affected data subject, capped at $50,000 per incident. Wiretap violations under Chapter 272, Section 99 carry criminal penalties of up to 5 years in state prison and a $10,000 fine.

Does 201 CMR 17.00 apply to businesses outside Massachusetts?

Yes. Any business that owns or licenses personal information about a Massachusetts resident must comply, regardless of where the business is located. A company in another state that stores the name and Social Security number of one Massachusetts resident must maintain a WISP and meet all technical controls in Section 17.04, including encryption of data in transit and at rest on portable devices, access controls, firewall protection, and employee training.

What does the TAKE IT DOWN Act mean for Massachusetts residents?

The TAKE IT DOWN Act (Pub. L. 119-12), signed May 19, 2025, is a federal law that criminalizes the knowing publication of nonconsensual intimate images, including AI-generated deepfakes. As of May 19, 2026, covered online platforms must maintain a notice-and-removal process and take down reported images within 48 hours. The FTC enforces the platform obligations and may seek civil penalties of $53,088 per violation. Massachusetts residents who are victims of nonconsensual intimate images can use the federal law alongside the Massachusetts state law signed by Governor Healey in June 2024.

What rights will Massachusetts residents gain when the Data Privacy Act becomes law?

The Senate and House have passed different versions of the Massachusetts Data Privacy Act, and a conference committee has been reconciling them since June 2026. Both versions would give residents the right to know what personal data is collected about them, access that data, correct inaccuracies, request deletion, and opt out of targeted advertising and data sales, plus a full ban on selling minors' personal data. The bills disagree on sensitive-data sales: the Senate version bans selling sensitive data, including health information, biometric identifiers, precise geolocation, religious affiliation, immigration status, sexual orientation, and race, outright, while the House version allows those sales with the consumer's affirmative consent, except for precise geolocation, which stays banned either way. The Senate version would take effect January 1, 2027; the House version delays implementation to July 1, 2027.

How do I report a data breach or privacy violation in Massachusetts?

You can file a complaint directly with the Massachusetts Attorney General's Data Privacy and Security Division at mass.gov. You can also contact the Office of Consumer Affairs and Business Regulation, which receives breach notifications. If a business that suffered a breach affecting you failed to notify you, or if you believe a company is violating your data rights under Chapter 93A, you can send a 30-day written demand letter before filing suit in Superior Court. For wiretap violations, contact the AG's Criminal Bureau.

Updates

Corrected the breach-notice content list so the parent or affiliated corporation name appears as a requirement of the notice to residents under M.G.L. c. 93H s.3(d) rather than the notice to regulators, reframed the Peabody Properties consent judgment as allegations the company settled rather than an adjudicated notification deadline, and clarified that 201 CMR 17.04 requires secure user authentication protocols and does not itself mandate multi-factor authentication.

Updated the status of the Massachusetts Data Privacy Act: the House did not simply leave the Senate's bill pending, it passed its own competing bill (H.5479, 146-0, June 2026) with a private right of action and different sensitive-data-sale rules, and a conference committee has been reconciling the two bills since June 2026 with no compromise bill yet signed. Also fixed a dead citation link for the Chapter 214, Section 1B right-of-privacy statute and untangled a duplicate citation entry.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

May 2026 refresh: Updated S.2608 legislative status (Senate passed 40-0 September 2025, House pending, not signed). Added Peabody Properties $795,000 settlement (August 2025). Added Earnest Operations $2.5M AI enforcement action. Added AG April 2024 AI advisory. Added S.43 biometric bill status. Added TAKE IT DOWN Act platform compliance effective May 19, 2026. Added Massachusetts June 2024 deepfake/NCII law. Added Chapter 93I records disposal coverage. Added federal overlay section. Updated FAQ to 8 questions. Corrected APRA status (expired 118th Congress, not reintroduced).

Reviewed and approved by an editor

Sources and References

  1. 201 CMR 17.00: Standards for the Protection of Personal Information(mass.gov).gov
  2. Mass. Gen. Laws ch. 93H - Security Breaches(malegislature.gov).gov
  3. Chapter 93H, Section 3 - Duty to Report Known Security Breach(malegislature.gov).gov
  4. Chapter 93H, Section 3A - Credit Monitoring Requirements(malegislature.gov).gov
  5. Chapter 93H, Section 1 - Definitions(malegislature.gov).gov
  6. Requirements for Data Breach Notifications(mass.gov).gov
  7. Chapter 93A - Consumer Protection Act(malegislature.gov).gov
  8. 201 CMR 17.04 - Computer System Security Requirements(law.cornell.edu)
  9. Massachusetts Data Privacy Act S.2608 - Fact Sheet(malegislature.gov).gov
  10. Senate Passes the Massachusetts Data Privacy Act(malegislature.gov).gov
  11. AG Data Privacy and Security Division(mass.gov).gov
  12. Mass. Gen. Laws ch. 214, Section 1B - Right of Privacy(malegislature.gov).gov
  13. 940 CMR 27.00: Safeguard of Personal Information(mass.gov).gov
  14. Mass. Gen. Laws ch. 272, Section 99 - Wiretap Statute(malegislature.gov).gov
  15. Massachusetts Student Records Regulations 603 CMR 23.00(doe.mass.edu).gov
  16. Guidance Regarding K-12 Schools Obligations to Protect Students(mass.gov).gov
  17. Reporting Data Breaches to the Attorney General(mass.gov).gov
  18. Chapter 93H, Section 6 - Enforcement(malegislature.gov).gov
  19. Massachusetts Law About Privacy(mass.gov).gov
  20. Data Breach Notification Reports(mass.gov).gov
  21. M.G.L. Chapter 93I: Dispositions and Destruction of Records(malegislature.gov).gov
  22. AG Campbell Reaches $795,000 Settlement with Peabody Properties for Data Security and Breach Notification Failures (August 2025)(mass.gov).gov
  23. AG Campbell Announces $2.5 Million Settlement with Earnest Operations for AI-Driven Consumer Protection Violations(mass.gov).gov
  24. Governor Healey Signs Bill Banning Revenge Porn and Deepfakes (June 20, 2024)(mass.gov).gov
  25. FTC: Take It Down Act Enforcement Starts Now (May 2026)(ftc.gov).gov
  26. Congressional Research Service: The TAKE IT DOWN Act(congress.gov).gov
  27. 603 CMR 23.00: Student Records Regulations, Massachusetts Department of Elementary and Secondary Education(doe.mass.edu)
  28. S.43 (SD2204): An Act to Protect Personal Biometric Data, Massachusetts 194th General Court(malegislature.gov).gov
  29. 201 CMR 17.00 - Standards for the Protection of Personal Information (official OCABR regulation text)(mass.gov)
Share: