Law / United States / Massachusetts

Standards for the Protection of Personal Information of Residents of the Commonwealth

201 CMR 17.01-17.05

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 1 March 2010.

A security baseline statutes rule binding private bodies.

As of 12 September 2026.

What it requires

  • This binds any person that owns or licenses personal information about a Massachusetts resident, meaning any person or business that receives, stores, maintains, processes, or otherwise has access to it in connection with providing goods or services or in connection with employment; it reaches a business outside Massachusetts that holds a Massachusetts resident's personal information the same as one located here.
  • Develop, implement, and maintain a comprehensive written information security program (WISP), in one or more readily accessible parts, with administrative, technical, and physical safeguards appropriate to your size, scope, resources, amount of stored data, and the sensitivity of the personal information you hold.
  • Designate one or more employees to maintain the WISP; identify and assess foreseeable internal and external risks to personal information and evaluate whether your safeguards limit them; train employees; discipline violations; cut off a terminated employee's access to records; restrict and secure physical access to records; review the WISP's scope at least annually or after a material change in business practice; document your response to any security-breach incident; and select only third-party service providers capable of maintaining appropriate security measures, requiring those measures by contract.
  • For personal information you store or transmit electronically, build a computer-system security program with secure user authentication, access controls limiting records to those who need them, encryption of records transmitted across public networks or wirelessly and of personal information stored on a laptop or other portable device, up-to-date firewalls and operating-system security patches for any internet-connected system, up-to-date malware protection, and employee training on the security system.
  • There is no compliance runway left to build against: every covered person has been required to be in full compliance since March 1, 2010.

If you get it wrong

Criminal exposureNo

Private right of actionYes

Penalty structure

M.G.L. ch. 93H, section 6 gives the Attorney General authority to bring an action under ch. 93A, section 4 to remedy a violation of chapter 93H, which this regulation implements. Ch. 93A, section 4 caps the civil penalty the court may impose at $5,000 for each violation the court finds a person knew or should have known violated ch. 93A, section 2, plus investigation and litigation costs including attorney's fees; a further civil penalty of up to $10,000 per violation applies to violating an injunction or order issued under section 4. 940 CMR 3.16(3) routes a violation of this regulation into that mechanism by deeming it a section 2 violation.

Rule
Per violation only
As of
12 September 2026
Currency
USD
Per violation unit
Violation
Per violation amount
5,000

Statutory damages

Ch. 93A, section 9(3): a private plaintiff recovers actual damages or $25, whichever is greater, trebled (or at minimum doubled) for a willful or knowing violation, plus attorney's fees and costs under section 9(4). Section 9(2) permits a class action for similarly injured persons. This route is opened by 940 CMR 3.16(3), which deems a failure to comply with a regulation meant to protect Massachusetts consumers, including this one, a ch. 93A, section 2 violation; ch. 93H, section 6 and this regulation carry no private-right-of-action language of their own.

As of
12 September 2026
Currency
USD
Per person minimum
25
Class action available
Yes

Who enforces it

Enforcement body

M.G.L. ch. 93H, section 6 authorizes the Attorney General to bring an action under ch. 93A, section 4 to remedy a violation of chapter 93H, which this regulation implements; separately, 940 CMR 3.16(3) deems a violation of this regulation a ch. 93A, section 2 unfair or deceptive practice, which arms any person injured by it to sue privately under ch. 93A, section 9.

What it reaches

Obligation class

Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Every person that owns or licenses personal information about a Massachusetts resident, meaning anyone who receives, stores, maintains, processes, or otherwise has access to it in connection with providing goods or services or in connection with employment, must develop, implement, and maintain a comprehensive written information security program (WISP) with administrative, technical, and physical safeguards appropriate to the business's size, scope, resources, amount of stored data, and the need for security and confidentiality of both consumer and employee information.

The WISP must designate one or more employees to maintain it, identify and assess reasonably foreseeable internal and external risks and evaluate the effectiveness of current safeguards, train employees, impose discipline for violations, cut off a terminated employee's access to records containing personal information, restrict and secure physical access to and storage of records, monitor the program's operation, and review its scope at least annually or after a material change in business practice.

It must also document the entity's response to any security-breach incident and oversee third-party service providers by taking reasonable steps to select and retain only ones capable of maintaining appropriate security measures and requiring those measures by contract.

Where personal information is stored or transmitted electronically, 17.04 adds a computer-system security program: secure user authentication, access controls limiting records to those who need them, encryption of records transmitted across public networks or wirelessly and of personal information stored on a laptop or other portable device, up-to-date firewall protection and operating-system security patches for a system connected to the internet, up-to-date malware protection, and employee training on the security system.

The regulation was promulgated by the Office of Consumer Affairs and Business Regulation under the rulemaking authority M.G.L. ch. 93H, section 2(a) grants it. It required full compliance by every covered person on or before March 1, 2010 (17.05). Ch. 93H, section 6 gives the Attorney General authority to bring an action under ch. 93A, section 4 to remedy a violation of chapter 93H, which this regulation implements (17.01(1)).

Separately, 940 CMR 3.16(3) deems a failure to comply with a statute or regulation meant to protect the public and intended to provide Massachusetts consumers protection, which includes this regulation, a ch. 93A, section 2 unfair or deceptive practice, opening a private right of action under ch. 93A, section 9 to any person injured by the deemed violation.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics
  • serves_minors
  • operates_social_platform
  • ships_mobile_app
  • distributes_software_product

Read the law

Official Code of Massachusetts Regulations text, Office of Consumer Affairs and Business Regulation, PDF from mass.gov

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app