Regulations › US states › Massachusetts

201 CMR 17.00

Massachusetts data security regulation

In force security
WhenIn effect since 1 March 2010
Who enforces itMassachusetts Attorney General
Who it applies toBusinesses that own or license personal information of Massachusetts residents.

One of the first prescriptive state security rules: a written information security program, encryption and vendor oversight.

The law in brief

201 CMR 17.00 is the Massachusetts data security regulation, in force since 2010. It was one of the first state rules to require a written information security program, and it still reads like a practical checklist: named responsibilities, risk assessment, training, vendor oversight and specific computer security controls.

It protects the personal information of Massachusetts residents, so it applies to organizations anywhere that hold that information, including employers with Massachusetts staff.

Who it applies to

  • Any person who owns or licenses personal information about a Massachusetts resident, in paper or electronic form. It covers businesses of all sizes; the program must be appropriate to size, resources, the amount of data and the need for security.
  • Personal information is a resident's first name or initial and last name combined with a Social Security number, a driver's license or state ID number, or a financial account or credit or debit card number.
  • It works alongside the Massachusetts breach notice law (M.G.L. c. 93H), which requires notice to the Attorney General and the Office of Consumer Affairs and Business Regulation as well as to residents.

What it requires

A written information security program

Keep a comprehensive written information security program with administrative, technical and physical safeguards appropriate to your size, resources, the data you hold and the need for security.

People, training and discipline

Designate employees to maintain the program, train staff, impose disciplinary measures for violations, and prevent terminated employees from accessing records.

Vendor oversight

Take reasonable steps to select service providers that can protect personal information, and require them by contract to maintain appropriate safeguards.

Computer security controls

Where technically feasible: secure authentication and access controls, encryption of data in transit over public networks and wirelessly, encryption on laptops and portable devices, monitoring, current patches and firewalls, malware protection, and security training.

Review and incident records

Review the program at least annually or when business practices change materially, and document responses to incidents and any changes made afterward.

Enforcement and penalties

The Attorney General enforces under M.G.L. c. 93H and the consumer protection statute, c. 93A, which allows civil penalties per violation, injunctive relief and costs. Settlements after breaches commonly cite the absence of a written program, encryption or vendor oversight.

What to do first

  1. Write the program down and name the employee or employees who maintain it.
  2. Assess risks to records containing personal information, including paper.
  3. Encrypt personal information on laptops and portable devices, and when sent over public networks or wirelessly.
  4. Contract with vendors to require appropriate safeguards, and check that they meet them.
  5. Cut off access promptly when employees leave.
  6. Review the program at least annually, and after any incident.

Checked against the official text on 28 September 2026. Quotations are the operative words of the law, linked to the article they come from; the official text is the authority. This brief is written by the Association for practitioners and is not legal advice.

Recent developments

Nothing reported yet. Regulatory Watch lists new rules, enforcement and court decisions as they arrive.

Sources