Massachusetts Privacy Law Explained.
Plain-English guide to the state’s data security regulation 201 CMR 17.00, breach notification under MGL c.93H, WISP requirements and what compliant disposal looks like.
Massachusetts has one of the strictest data security regulations in the country. Any business that holds personal information of Massachusetts residents falls under 201 CMR 17.00, regardless of where the business is located. Combined with the breach notification statute MGL c.93H and active enforcement by the state Attorney General, the Massachusetts privacy framework demands serious compliance attention.
This guide explains 201 CMR 17.00, the breach notification statute, the Written Information Security Program (WISP) requirement, the disposal expectations and the practical compliance steps for metro Boston businesses.
What 201 CMR 17.00 Requires
201 CMR 17.00 applies to any person who owns or licenses personal information about Massachusetts residents. The trigger is information about MA residents, not the business location. A Texas-based company holding personal information about MA residents is covered.
Personal information is defined as a Massachusetts resident’s first name (or initial) and last name combined with at least one of:
- Social Security number
- Driver’s license number or state ID number
- Financial account number
- Credit or debit card number with security code or password
- Biometric information used to authenticate identity
Email addresses, phone numbers and physical addresses alone do not trigger the regulation. The combination of name and one of the protected elements does.
The WISP Requirement
The headline requirement is the Written Information Security Program. Every covered business must develop, implement, maintain and review a comprehensive WISP. Required elements include:
- Designated employee responsible for the program
- Identification and assessment of foreseeable internal and external risks
- Reasonable security measures responsive to those risks
- Written policies for storage, access and transportation of personal information
- Restrictions on access to records and information
- Disciplinary measures for violations
- Termination procedures preventing access by departing employees
- Service provider oversight including contracts requiring comparable safeguards
- Reasonable restrictions on physical access
- Regular monitoring of the program’s effectiveness
- Review at least annually or whenever there is a material change to business practices
- Documentation of responsive actions taken in connection with breaches
For computerized records, the WISP must specifically address user authentication, access controls, encryption of transmitted information, monitoring of system access, encryption of laptops and portable devices, firewall and operating system patches, malware protection and ongoing employee training.
Disposal Under 201 CMR 17.00
Disposal is one of the explicit safeguards required in any WISP. The regulation requires “secure storage and disposal of paper records containing personal information.” In practice, this means:
Storage of paper records in locked file cabinets, locked offices, locked file rooms or secured electronic systems with access controls.
Disposal of paper records through cross-cut shredding, burning, pulping or pulverizing so that personal information cannot be read or reconstructed. The same standard the FTC FACTA Disposal Rule uses.
Disposal of electronic media through physical destruction or cryptographic sanitization so the information cannot be retrieved.
Documentation of disposal events, typically through Certificates of Destruction from a third-party vendor or internal destruction logs.
Service provider oversight, including written contracts with destruction vendors that require comparable safeguards. Our standard service contract satisfies the 201 CMR 17.00 service provider requirement.
Massachusetts Breach Notification (MGL c.93H)
MGL c.93H is the breach notification statute that pairs with 201 CMR 17.00. Any breach of personal information triggers reporting obligations to:
- The Attorney General
- The Office of Consumer Affairs and Business Regulation
- Each affected Massachusetts resident
Notice must include the date of the breach, types of information involved, steps the business has taken or plans to take in response and information about credit monitoring (which the business must offer in many cases). For breaches involving 1,000+ MA residents, additional disclosure to consumer reporting agencies is required.
Timing matters. Notice must be provided “as soon as practicable and without unreasonable delay” after discovery. The Massachusetts AG has been consistent in interpreting “without unreasonable delay” tightly, often expecting notice within 30 to 60 days of discovery.
Penalties and Enforcement
Massachusetts enforcement is among the most active in the country. The AG’s Data Privacy and Security Division pursues investigations and settlements regularly.
Violations of 201 CMR 17.00 carry civil penalties up to $5,000 per violation under MGL c.93A (the consumer protection statute). When breaches affect thousands of residents, aggregated penalties reach the millions.
Recent settlements include cases where businesses failed to maintain a WISP, lacked documented disposal practices, or breached personal information through unsecured paper or electronic disposal. Settlements have ranged from $25,000 for small businesses to $5+ million for larger entities.
Beyond civil penalties, breaches under MGL c.93H trigger:
- Mandatory consumer notification (typically by mail, sometimes by email)
- Free credit monitoring offers, often 12 to 24 months
- Class action lawsuits from affected residents
- Reputational damage covered in local Boston-area press
- Increased insurance premiums on cyber and general liability policies
Practical Compliance Steps
Six steps for a compliant Massachusetts privacy program.
Step 1: Build the WISP. Use a template tailored to your industry. Add specific provisions for storage, access, transportation, disposal and termination. Get sign-off from leadership.
Step 2: Engage compliant disposal vendors. Cross-cut shredding for paper, NIST 800-88 destruction for electronic media, with Certificates documenting every event.
Step 3: Train staff. Annual training on the WISP, what counts as personal information and how to handle disposal. Document the training.
Step 4: Audit annually. Review the WISP, test the controls and document findings. Update for any material changes (new systems, new vendors, new business lines).
Step 5: Plan for incidents. Have an incident response plan that names who handles a breach, how forensics work, when AG notification triggers and what consumer notification looks like.
Step 6: Document everything. WISP, training records, disposal Certificates, audit findings, vendor contracts. In an investigation, documentation is what separates a quick resolution from a multi-year settlement process.
For Massachusetts business owners who have not formalized their WISP yet, the right time to start is now. Massachusetts AG investigations almost always begin by requesting the WISP. Without one, the conversation gets harder fast. With a current and well-documented WISP backed by Certificates of Destruction proving compliant disposal, AG investigations resolve far faster and with smaller penalties when penalties apply at all.
Industries With the Heaviest Massachusetts Compliance Burden
Five industries handle the most personal information about Massachusetts residents and consequently face the heaviest 201 CMR 17.00 compliance burden.
Healthcare. Patient records, billing files, employee records all contain personal information. HIPAA and 201 CMR 17.00 overlap heavily for medical practices. See our HIPAA medical shredding pillar.
Financial Services. Banking, investment advice, insurance, mortgage broking. GLBA and 201 CMR 17.00 stack here. Most financial firms maintain unified WISPs covering both. See our GLBA explainer.
Real estate and property management. Tenant screening pulls credit reports. Closings handle Social Security numbers and bank information. Property management firms holding tenant files for years face concentrated 201 CMR 17.00 exposure.
Education. Schools, universities and educational service providers hold student personal information including Social Security numbers and financial aid documentation. FERPA layers on top of 201 CMR 17.00.
HR and staffing services. Employee files, candidate background checks, payroll data, benefits enrollments. Multi-employer staffing firms accumulate substantial personal information that triggers 201 CMR 17.00 obligations.
Across all five sectors, professional shredding service is the practical answer to the disposal element of the WISP. We serve clients in each of these industries across our 14-city footprint with documentation that satisfies 201 CMR 17.00 and the related federal frameworks simultaneously.
Massachusetts Privacy Law FAQ
Does the law apply if we are based outside Massachusetts?
What about businesses with only a few MA customers?
How does this compare to GDPR or CCPA?
Do we need separate WISPs for HIPAA and 201 CMR 17.00?
What if we discover a breach? When do we have to report?
Can paper records alone trigger 201 CMR 17.00 obligations?
201 CMR 17.00 Compliant Destruction.
WISP-ready service contracts, documented destruction, Certificates that hold up under Massachusetts AG scrutiny.
Comments are closed.