Law / United States / Massachusetts

Massachusetts

United States law applies in Massachusetts Massachusetts is a state of the United States, whose 32 researched instruments are listed on the United States page, not here. The law of Massachusetts, described on this page below, applies here too.

13 of 19 named instruments researched to a stage, across five of the six areas of law we track: 4 in force, 4 enacted but not yet in force and 5 proposed. As of 12 September 2026.

  1. AI law 2
  2. Privacy law 5
  3. Scraping law 3
  4. Cybersecurity law 1
  5. Age gating law 2
  6. News aggregation law none researched

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law2 instruments, 2 proposed

Research summary (231 words)

Massachusetts has not enacted a general-purpose AI-transparency or disclosure statute.

The Attorney General's April 2024 advisory takes the position that existing consumer-protection law (chapter 93A), civil-rights statutes, and the data-security regulation at 201 CMR 17.00 already reach deceptive, discriminatory, or insecure uses of AI; because the duty in each case attaches to consumer protection or data security generally rather than to an AI system specifically, none of those instruments is catalogued here as an AI-specific finding.

Two bills targeting AI in elections passed the House on February 11, 2026 and are pending before the Senate Committee on Ways and Means: one bans distributing deceptive AI-generated or manipulated media about a candidate or an election within 90 days of that election, and the other requires that AI-generated synthetic media used in political advertising disclose that fact at the start and end of the communication.

Other AI bills remain earlier in the process: a consumer-chatbot-protection bill (S.264) was reported favorably by its Senate committee in December 2025 and now sits in Senate Ways and Means; a general AI-disclosure bill (H.81) was sent to a study order in February 2026, which in Massachusetts practice ends its progress for this session without further action; and bills addressing AI in behavioral-health utilization review (S.2632) and algorithmic non-discrimination (SD.3007/HD.4827) have not been confirmed past initial committee referral. None of the four is catalogued here as an instrument.

AI prohibited practices

An Act to Protect Against Election Misinformation (H.5093)

H.5093, 194th General Court (2025-2026)official bill history, Massachusetts Legislature

Proposed: draft date not recorded. Binds public and private bodies.

What this law does

This bill has not been enacted, so read the following as what it would require rather than a current duty.

As passed by the House, it would prohibit distributing deceptive audio or visual media within 90 days of an election, covering media depicting a candidate with intent to injure their reputation or deceive a voter, media intended to disrupt the safety or regular operation of an election, and media intended to mislead voters about voting dates, methods, or deadlines, election certification, or a false endorsement.

A candidate whose voice or likeness appears in such media may seek injunctive relief or bring an action for damages and attorney's fees against the distributing party. Exemptions cover media outlets that air or report on the content while acknowledging authenticity questions, websites, newspapers, magazines and periodicals, and satire and parody. Originally filed as H.76, the House Committee on Ways and Means reported a new draft as H.5093.

The redraft passed the House 154 to 3 on February 11, 2026. It was then referred to the Senate Committee on Ways and Means on February 12, 2026.

What it requires

AI transparency

An Act enhancing disclosure requirements for synthetic media in political advertising (H.5094)

H.5094, 194th General Court (2025-2026)official bill history, Massachusetts Legislature

Proposed: draft date not recorded. Binds public and private bodies.

What this law does

This bill has not been enacted, so read the following as what it would require rather than a current duty. As passed by the House, any synthetic media audio or video communication intended to influence voting for or against a candidate or a ballot proposition would have to disclose, at the beginning and the end of the communication, that it contains AI-generated material. A violation would be punishable by a fine of not more than $1,000.

Originally filed as H.846, the House Committee on Ways and Means reported a new draft as H.5094. The redraft passed the House 157 to 0 on February 11, 2026. It was then referred to the Senate Committee on Ways and Means on February 12, 2026.

What it requires

Privacy law5 instruments, 4 enacted but not yet in force, 1 proposed

Research summary (196 words)

Massachusetts has no comprehensive consumer-privacy statute in force. The Massachusetts Data Privacy Act (MDPA), which would establish one, passed the Senate 40-0 as S.2608/S.2619 and the House 146-0 in an amended form (H.5472, republished as H.5479), but the Senate non-concurred in the House amendment on June 11, 2026 and the bill remains in a conference committee with no compromise text produced. Massachusetts's in-force privacy law is a security-breach statute, Mass.

Gen. Laws ch. 93H, and its implementing regulation, 201 CMR 17.00, neither of which defines or reaches biometric data at all; genetic information is protected only as an employment-discrimination category under ch. 151B, not as a data-processing right.

Chapter 93H's own enforcement clause arms only the Attorney General, but a private right of action for a ch. 93H or 201 CMR 17.00 violation opens through a separate, third instrument: 940 CMR 3.16(3), an Attorney General consumer-protection regulation issued under ch. 93A's own rulemaking power, deems a failure to comply with a consumer-protection statute or regulation an unfair or deceptive act under ch. 93A section 2, which ch. 93A section 9 then arms a private plaintiff to sue on for damages, trebled if knowing, plus attorney fees.

Breach notification

Security Breach statute, credit monitoring offer required

Mass. Gen. Laws ch. 93H, § 3Aofficial Massachusetts General Laws text, Massachusetts Legislature

Commencement not set. Binds public and private bodies.

What this law does

If a resident's Social Security number was disclosed or reasonably believed disclosed in a breach, the person or agency that experienced the breach must contract with a third party to offer that resident credit monitoring services at no cost for not less than 18 months. If the entity that experienced the breach is itself a consumer reporting agency, it must instead offer not less than 42 months of free credit monitoring.

The entity may not require a resident to waive any right to a private right of action as a condition of the credit-monitoring offer.

What it requires

Security Breach statute, duty to report breach of personal information

Mass. Gen. Laws ch. 93H, § 3official Massachusetts General Laws text, Massachusetts Legislature

Commencement not set. Binds public and private bodies.

What this law does

Massachusetts's Security Breach statute, Mass. Gen. Laws ch. 93H, first enacted 2007, requires a person or agency that owns or licenses data including a resident's personal information to notify the Attorney General, the Director of Consumer Affairs and Business Regulation, and the affected resident as soon as practicable and without unreasonable delay upon learning of a breach of security or unauthorized acquisition or use.

Personal information is a resident's name combined with a Social Security number, driver's license or state ID number, or financial account or card number, and excludes information lawfully obtained from publicly available sources or government records; it does not define or reach biometric data at all.

What it requires

Comprehensive regime

Massachusetts Data Privacy Act (MDPA)

Mass. S.2619 (formerly S.2608); House substitute H.5472/H.5479, 194th Gen. Ct.official Massachusetts Legislature bill history, malegislature.gov

Proposed: draft date not recorded. In reconciliation between two chambers, dated 17 June 2026, as of 12 September 2026. Binds private bodies.

What this law does

The Massachusetts Data Privacy Act (MDPA) would establish the state's first comprehensive consumer personal-data regime; it is not enacted and imposes no duty today. Originally S.2608, it passed the Senate 40-0 on September 25, 2025, was engrossed as S.2619, and was amended by the House (Ways and Means reported a substitute striking the text and inserting H.5472, itself amended and republished as H.5479) before passing the House 146-0 on June 4, 2026.

The Senate non-concurred in the House amendment on June 11, 2026 and appointed a conference committee; the House insisted on its own amendment and appointed its own conferees on June 17, 2026. As of the date shown, the bill remains in conference with no compromise text produced.

What it requires

Enforcement supervision

Consumer Protection General Regulations, deeming a data-security violation an unfair practice

940 CMR 3.16(3); Mass. Gen. Laws ch. 93A, §§ 2, 9official Code of Massachusetts Regulations text, Office of the Attorney General, PDF from mass.gov

Commencement not set. Binds private bodies.

What this law does

A private right of action for a Massachusetts data-security violation opens through a separate Attorney General consumer-protection regulation, not through ch. 93H or 201 CMR 17.00 directly.

940 CMR 3.16, promulgated under ch. 93A section 2(c), provides that an act or practice violates ch. 93A section 2 if, among other things, it fails to comply with an existing statute, rule, or regulation meant for the protection of the public's health, safety, or welfare and intended to provide Massachusetts consumers protection.

A failure to comply with ch. 93H's breach-notice duty or 201 CMR 17.00's WISP mandate is therefore a ch. 93A section 2 violation, which ch. 93A section 9 arms any injured person to sue on for damages, trebled if the violation was knowing, plus attorney fees. Chapter 93H section 6 alone does not open this route; the mechanism is entirely this separate regulation.

What it requires

Security Breach statute, Attorney General enforcement

Mass. Gen. Laws ch. 93H, § 6official Massachusetts General Laws text, Massachusetts Legislature

Commencement not set. Binds public and private bodies.

What this law does

Chapter 93H's own enforcement clause lets the Attorney General bring an action under ch. 93A section 4 to remedy a violation. On its own face, this section creates no private right of action: it does not deem a ch. 93H violation to be an unfair or deceptive practice actionable by a private plaintiff under ch. 93A section 9. A private right of action for a ch. 93H violation exists only through a separate Attorney General regulation, 940 CMR 3.16(3).

What it requires

Scraping law3 instruments, 3 in force

Research summary (127 words)

Massachusetts adds its own criminal computer-crime statutes on top of the federal baseline: unauthorized access to a computer system is a standalone state offense turning on the same password-or-authentication gate the Computer Fraud and Abuse Act (CFAA) uses, and a separate section reaches fraudulently obtaining a subscription-based commercial computer service. Neither section carries a private civil right of action of its own.

The state's principal civil vehicle for a scraping-adjacent claim is chapter 93A's unfair-or-deceptive-practices statute, the same California-style role its Unfair Competition Law plays there, which arms a private plaintiff with double or treble damages for a willful violation.

No Massachusetts appellate decision addressing browsewrap or clickwrap enforceability, database rights, or robots.txt's legal weight specifically has been located; those dimensions rest on the federal-law baseline already covered in the national document.

Computer misuse

Obtaining computer services by fraud or misrepresentation; penalties

Mass. Gen. Laws ch. 266, § 33Aofficial text, Massachusetts General Laws, malegislature.gov

In force. Binds public and private bodies.

What this law does

Whoever, with intent to defraud, obtains or attempts to obtain a commercial computer service by false representation, false statement, unauthorized charging to another's account, tampering with equipment, or any other means, is punished by up to two and one-half years in the house of correction, a fine of up to $3,000, or both.

"Commercial computer service" is defined as the use of, or access to or copying of data from, a computer, system, program, or network that its proprietor offers to others on a subscription or other paid basis, so the section reaches circumventing a paywall or subscription gate rather than accessing an openly published page. The codified text carries no session-law citation or amendment history showing a specific commencement day.

What it requires

Unauthorized access to a computer system; penalties

Mass. Gen. Laws ch. 266, § 120Fofficial text, Massachusetts General Laws, malegislature.gov

In force. Binds public and private bodies.

What this law does

Whoever, without authorization, knowingly accesses a computer system by any means, or after gaining access by any means knows that access is not authorized and fails to terminate it, is punished by up to 30 days in the house of correction, a fine of up to $1,000, or both.

The section states that a password or other authentication requirement itself constitutes notice that access is limited to authorized users, the same authorization-gate reasoning the Computer Fraud and Abuse Act (CFAA)'s federal case law uses, so a public, unauthenticated page raises no exposure under this section on the same logic. The codified text carries no session-law citation or amendment history showing a specific commencement day.

What it requires

Unfair competition

Unfair or deceptive acts or practices (predicate vehicle for scraping claims)

Mass. Gen. Laws ch. 93A, §§ 2, 9official text, Massachusetts General Laws, malegislature.gov

In force. Binds private bodies.

What this law does

Section 2 declares unfair methods of competition and unfair or deceptive acts or practices in trade or commerce unlawful, directing courts to be guided by FTC Act Section 5 interpretations, the same federal standard chapter 93A imports. Section 9 arms any person injured by such conduct with a private civil action for damages and equitable relief, including an injunction. A willful or knowing violation exposes the defendant to up to three, but not less than two, times the actual damages found.

What it requires

Cybersecurity law1 instrument, 1 in force

Research summary (860 words)

Massachusetts's product-security and baseline-security posture rests on one enacted regulation with its own enabling statute, layered over the federal-level regimes already researched as this jurisdiction's national row and not repeated here.

201 CMR 17.00, Standards for the Protection of Personal Information of Residents of the Commonwealth, promulgated by the Office of Consumer Affairs and Business Regulation under the rulemaking authority M.G.L. ch. 93H, section 2(a) grants it, requires every person who owns or licenses personal information about a Massachusetts resident, reaching anyone who receives, stores, maintains, processes, or otherwise has access to it in connection with providing goods or services or in connection with employment, to develop, implement, and maintain a comprehensive written information security program (WISP), in one or more readily accessible parts, with administrative, technical, and physical safeguards appropriate to the business's size, resources, amount of stored data, and the sensitivity of the information (17.03(1)).

The WISP must designate one or more employees to maintain it, identify and assess foreseeable internal and external risks, train employees, impose discipline for violations, cut off a terminated employee's access, restrict physical access and require locked storage, monitor the program's operation, review its scope at least annually or after a material change in business practice, oversee third-party service providers by selecting only ones capable of maintaining appropriate security measures and requiring those measures by contract, and document the entity's response to any security-breach incident (17.03(2)).

Where personal information is stored or transmitted electronically, 17.04 layers on a computer-system security program: secure user authentication, access controls limiting records to those who need them, encryption of records transmitted across public networks or wirelessly and of personal information stored on a laptop or other portable device, reasonable monitoring for unauthorized use, up-to-date firewalls and operating-system security patches for an internet-connected system, up-to-date malware protection, and employee training on the computer security system.

Every covered person had to be in full compliance by March 1, 2010 (17.05); there is no forward compliance runway left to describe.

Ch. 93H, section 6 gives the Attorney General authority to bring an action under ch. 93A, section 4 to remedy a violation of 'this chapter,' which 201 CMR 17.00 implements by its own text (17.01(1)); separately, 940 CMR 3.16(3), a general Attorney General consumer-protection regulation promulgated under ch. 93A, section 2(c), deems a failure to comply with a statute or regulation meant to protect the public and intended to provide Massachusetts consumers protection, which reaches 201 CMR 17.00, a ch. 93A, section 2 unfair or deceptive practice; that in turn opens ch. 93A, section 9 to any person injured by the deemed violation, recoverable as actual damages or $25, whichever is greater, trebled (or at minimum doubled) for a willful or knowing violation, plus attorney's fees, with a class action available under section 9(2), while the Attorney General may separately recover a civil penalty of up to $5,000 per violation under ch. 93A, section 4.

No Massachusetts statute sets security requirements a connected device or software product must meet before or after it reaches the market. The closest is S.3190 (194th Gen. Ct.), a redraft the Joint Committee on Consumer Protection and Professional Licensure reported favorably on July 22, 2026 from the original petition S.3090 (filed as Senate docket SD.3606 on January 16, 2026 by Senators William N. Brownsberger and David M. Rogers), now pending before the Senate Committee on Ways and Means.

As filed, it would require a manufacturer of a connected consumer product manufactured on or after January 1, 2026 to disclose a minimum guaranteed support period for technical support, security updates, and bug fixes, to notify consumers at least six months before end-of-life of the cybersecurity and other risks of continued use, and would require an internet service provider that supplies or leases such a product to keep it receiving security updates or replace it at no cost once the product reaches end-of-life; a violation would be an unfair or deceptive practice under ch. 93A, section 2.

It has not been enacted, so this is a researched absence rather than a gap in this profile's coverage, and the quoted provisions are the bill as introduced (S.3090); the committee's redraft, S.3190, has not itself been read for a possibly different set of terms. No Massachusetts cyber-resilience regime binding a class of entity by sector, criticality, or size, comparable to NIS2 or DORA, was located that reaches a digital service this corpus can currently flag against.

Massachusetts has no general private-sector duty to report an exploited vulnerability or a security incident, as distinct from a personal-data breach, to an authority; no analogue to New York's Chapter 177 (binding only government bodies) or to the federal Cyber Incident Reporting for Critical Infrastructure Act (not yet implemented) was found reaching a private business here.

Massachusetts's breach-notification duty, ch. 93H, section 3 (with the credit-monitoring offer at section 3A for a breach touching a Social Security number), is already this jurisdiction's privacy row rather than repeated here: it and 201 CMR 17.00 sit in the same chapter, with the breach-notice duty attaching to the exposure of personal data and the WISP duty attaching to the security program that would have prevented it.

Security baseline statutes

Standards for the Protection of Personal Information of Residents of the Commonwealth

201 CMR 17.01-17.05Official Code of Massachusetts Regulations text, Office of Consumer Affairs and Business Regulation, PDF from mass.gov

In force since 1 March 2010. Binds private bodies.

What this law does

Every person that owns or licenses personal information about a Massachusetts resident, meaning anyone who receives, stores, maintains, processes, or otherwise has access to it in connection with providing goods or services or in connection with employment, must develop, implement, and maintain a comprehensive written information security program (WISP) with administrative, technical, and physical safeguards appropriate to the business's size, scope, resources, amount of stored data, and the need for security and confidentiality of both consumer and employee information.

The WISP must designate one or more employees to maintain it, identify and assess reasonably foreseeable internal and external risks and evaluate the effectiveness of current safeguards, train employees, impose discipline for violations, cut off a terminated employee's access to records containing personal information, restrict and secure physical access to and storage of records, monitor the program's operation, and review its scope at least annually or after a material change in business practice.

It must also document the entity's response to any security-breach incident and oversee third-party service providers by taking reasonable steps to select and retain only ones capable of maintaining appropriate security measures and requiring those measures by contract.

Where personal information is stored or transmitted electronically, 17.04 adds a computer-system security program: secure user authentication, access controls limiting records to those who need them, encryption of records transmitted across public networks or wirelessly and of personal information stored on a laptop or other portable device, up-to-date firewall protection and operating-system security patches for a system connected to the internet, up-to-date malware protection, and employee training on the security system.

The regulation was promulgated by the Office of Consumer Affairs and Business Regulation under the rulemaking authority M.G.L. ch. 93H, section 2(a) grants it. It required full compliance by every covered person on or before March 1, 2010 (17.05). Ch. 93H, section 6 gives the Attorney General authority to bring an action under ch. 93A, section 4 to remedy a violation of chapter 93H, which this regulation implements (17.01(1)).

Separately, 940 CMR 3.16(3) deems a failure to comply with a statute or regulation meant to protect the public and intended to provide Massachusetts consumers protection, which includes this regulation, a ch. 93A, section 2 unfair or deceptive practice, opening a private right of action under ch. 93A, section 9 to any person injured by the deemed violation.

What it requires

Age gating law2 instruments, 2 proposed

Research summary (155 words)

Massachusetts has not yet enacted an age-gating statute, but both chambers of the legislature passed distinct social media bills for minors in 2026 that must be reconciled before either can reach the Governor.

The House passed its version on April 8, 2026 by substituting the text of H.5349 into S.2581, a Senate passed school cellphone bill; it would bar platforms from allowing accounts for users under 14 and would require verifiable parental consent for 14 and 15 year olds, using the best available age verification technology. The Senate non-concurred and a conference committee was appointed in May 2026.

The Senate separately passed S.3164 on July 9, 2026, which would instead require platforms to disable addictive design features, such as autoplay, infinite scroll, and algorithmic feeds, by default for minors, using an age verification method that need not rely solely on government ID. No adult content or app store age verification bill has advanced in Massachusetts.

Social media and minors

S.2581 as amended by the House (text of H.5349), An Act to promote student learning and mental health

Senate Bill No. 2581, 194th General Court, as amended by the House with the text of House Bill No. 5349official bill history and House press release, Massachusetts Legislature

Proposed: draft date not recorded. Binds private bodies.

What this law does

As passed by the House, would bar social media platforms from allowing an account for a user under 14, require termination and deletion of existing under-14 accounts by October 1, 2026, and require verifiable parental consent for 14 and 15 year old users, verified through the best available age verification technology, alongside a school day cellphone ban.

The House engrossed it 129 to 25 on April 8, 2026 by substituting the text of H.5349; the Senate non-concurred on May 7, 2026 and the bill is in a six member conference committee.

Note and primary source

S.3164 (2026), An Act protecting children from addictive social media feeds

Senate Bill No. 3164, 194th General Courtofficial bill text and Senate press release, Massachusetts Legislature

Proposed: draft date not recorded. Binds private bodies.

What this law does

Would require social media platforms to disable, by default, algorithmic feeds, autoplay, infinite scroll, and other addictive design features on minors' accounts, send reminders after extended use, and turn off notifications overnight. Requires an age verification method that need not rely solely on government issued identification. Passed the Senate 38 to 2 on July 9, 2026, and is now before the House, which took a different under-14 ban approach in its own bill.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.