EnglishEspañol
Massachusetts flag

Massachusetts

Massachusetts Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 10 primary sources cited on this page. How we verify our legal content

Massachusetts Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Frequently Asked Questions

How quickly must a business notify Massachusetts residents of a data breach?

Massachusetts requires notification "as soon as practicable and without unreasonable delay" after discovering a breach. There is no fixed deadline measured in days. The Attorney General evaluates whether the timing was reasonable given the scope of the breach and the investigation required.

Does Massachusetts require a Written Information Security Program (WISP)?

Yes. Under 201 CMR 17.00, every person or entity that owns or licenses personal information of Massachusetts residents must develop, implement, and maintain a comprehensive WISP. The program must include administrative, technical, and physical safeguards proportional to the organization's size, resources, and data volume. Failure to maintain a WISP can result in enforcement action by the Attorney General.

Can individuals sue for data breach notification violations in Massachusetts?

Yes. Massachusetts is one of the few states that provides a private right of action for breach notification violations. Through Chapter 93A, the state's consumer protection statute, individuals can file civil claims. If the court finds a willful or knowing violation, it can award treble damages plus attorneys' fees. A 30-day pre-suit demand letter is required before filing.

What encryption standard satisfies the Massachusetts safe harbor?

Massachusetts defines encryption as the transformation of data through a 128-bit or higher algorithmic process into a form with low probability of meaningful interpretation without the confidential key. If breached data meets this standard and the encryption key was not also compromised, the breach does not trigger notification requirements.

Is credit monitoring required after a Massachusetts data breach?

Credit monitoring is required when a breach involves Social Security numbers. The breached entity must offer free credit monitoring for at least 18 months through a third-party provider. If the breached entity is a consumer reporting agency, the minimum period is 42 months. Affected residents cannot be required to waive their right to sue as a condition of accepting monitoring services.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected the deadline for a third-party data custodian to notify the data owner of a breach: Massachusetts law requires notice as soon as practicable and without unreasonable delay, not immediately.

Corrected two mislinked citations to Chapter 93A, fixed a paragraph that misstated the scope of the federal-compliance safe harbor in M.G.L. c. 93H Section 5 (it exempts the notification duty, not the 201 CMR 17.00 security-program requirement), and clarified that the $16 million and $39.5 million enforcement figures are multistate settlement totals, with Massachusetts receiving about $625,000 and $1.4 million respectively.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Mass. Gen. Laws ch. 93H - Security Breaches(malegislature.gov).gov
  2. Chapter 93H Section 1 - Definitions(malegislature.gov).gov
  3. Chapter 93H Section 3 - Duty to Report(malegislature.gov).gov
  4. Chapter 93H Section 3A - SSN Breach Credit Monitoring(malegislature.gov).gov
  5. 201 CMR 17.00 - WISP Standards(mass.gov).gov
  6. 201 CMR 17.03 - Duty to Protect Standards(law.cornell.edu)
  7. 201 CMR 17.04 - Computer System Security Requirements(law.cornell.edu)
  8. MA AG - Reporting Data Breaches(mass.gov).gov
  9. OCABR - Reporting Data Breaches(mass.gov).gov
  10. AG Campbell $795K Settlement (2025)(mass.gov).gov
  11. AG Healey $16M Experian/T-Mobile Settlement(mass.gov).gov
  12. AG Healey $39.5M Insurance Company Settlement(mass.gov).gov
Share: