Law / United States /
Massachusetts
Consumer Protection General Regulations, deeming a data-security violation an unfair practice
940 CMR 3.16(3); Mass. Gen. Laws ch. 93A, §§ 2, 9
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
Commencement not set.
An enforcement supervision rule binding private bodies.
As of 2 September 2026.
What it requires
- Comply with ch. 93H's breach-notice duty and 201 CMR 17.00's information security program mandate. Noncompliance with either is a ch. 93A section 2 unfair or deceptive practice under 940 CMR 3.16(3), and any injured person may sue for damages, trebled if knowing, plus attorney fees, under ch. 93A section 9.
If you get it wrong
Criminal exposureNo
Private right of actionYes
Penalty structure
Ch. 93A sec. 4: the Attorney General may recover a civil penalty of up to $5,000 for each violation the court finds a person knew or should have known violated ch. 93A sec. 2, plus investigation and litigation costs including attorney's fees; a further civil penalty of up to $10,000 per violation applies to violating an injunction or order issued under sec. 4. 940 CMR 3.16(3) routes a data-security violation into this mechanism by deeming it a sec. 2 violation.
- Rule
- Per violation only
- As of
- 2 September 2026
- Currency
- USD
- Per violation unit
- Violation
- Per violation amount
- 5,000
Statutory damages
Ch. 93A sec. 9(1): a private plaintiff recovers actual damages or $25, whichever is greater; the court trebles the award, or at minimum doubles it, for a willful or knowing violation, plus attorney's fees and costs under sec. 9(4). Sec. 9(2) permits a class action for similarly injured persons.
- As of
- 2 September 2026
- Currency
- USD
- Per person minimum
- 25
- Class action available
- Yes
Who enforces it
Enforcement body
Massachusetts Attorney General (a civil penalty of up to $5,000 per violation and injunctive relief under ch. 93A sec. 4) and, privately, any person injured by the deemed unfair practice under ch. 93A sec. 9.
What it reaches
Obligation class
Security, Breach notice
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
A private right of action for a Massachusetts data-security violation opens through a separate Attorney General consumer-protection regulation, not through ch. 93H or 201 CMR 17.00 directly.
940 CMR 3.16, promulgated under ch. 93A section 2(c), provides that an act or practice violates ch. 93A section 2 if, among other things, it fails to comply with an existing statute, rule, or regulation meant for the protection of the public's health, safety, or welfare and intended to provide Massachusetts consumers protection.
A failure to comply with ch. 93H's breach-notice duty or 201 CMR 17.00's WISP mandate is therefore a ch. 93A section 2 violation, which ch. 93A section 9 arms any injured person to sue on for damages, trebled if the violation was knowing, plus attorney fees. Chapter 93H section 6 alone does not open this route; the mechanism is entirely this separate regulation.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreach
Read the law
official Code of Massachusetts Regulations text, Office of the Attorney General, PDF from mass.gov
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.