Massachusetts
The obligation almost nobody sells against
Massachusetts requires a written information security program from every person who holds a resident's personal information. There is no employee count threshold and no revenue floor. A one-person firm with one Massachusetts client is in scope.
What counts as personal information
A Massachusetts resident's name, first initial and last name or first and last name, combined with any one of the following:
- Social Security number
- Driver's license number or state-issued identification card number
- Financial account number, or credit or debit card number, with any access credential that would permit access to the account
If you prepare a Massachusetts resident's tax return, you hold the first of these. The question of whether the regulation applies to you is usually not close.
201 CMR 17.02 DefinitionsThe program
Ten elements your written program must contain
Comprehensive information security program
201 CMR 17.03(2)(a) through (j)
The controls
Eight computer system security requirements
To the extent technically feasible, these are the controls the regulation names.
Computer system security requirements
201 CMR 17.04(1) through (8)
What else Massachusetts law puts on you
Breach notification
Chapter 93H requires notice to the Attorney General, to the Director of Consumer Affairs and Business Regulation, and to the affected resident.
M.G.L. c. 93HSecure destruction
Chapter 93I governs the disposal of records containing personal information, in both paper and electronic form.
M.G.L. c. 93IConsumer protection exposure
Failures can be pursued under Chapter 93A. In the business-to-business provision, a willful or knowing violation carries two to three times damages and an award of attorney's fees to the prevailing party.
M.G.L. c. 93A §§ 9, 11Vendor flow-down
Because 17.03(2)(f) requires you to impose safeguards on your service providers by contract, your own clients and referral partners are required to impose them on you.
201 CMR 17.03(2)(f)Correct a common assumption
Massachusetts does not currently have a comprehensive consumer privacy law of the California type. The Massachusetts Data Privacy Act has moved through both chambers and, as of the last date this page was reviewed, had not been enacted. Do not plan against a statute that is not law, and do not let anyone sell you compliance with one. The operative duties today are 201 CMR 17.00 and Chapters 93H and 93I.
Legislative status changes. Confirm the current position with Massachusetts counsel before relying on this paragraph.
How ProtPTX handles it
One intake, two regimes, one document set
You answer the intake once. ProtPTX maps your answers against the federal elements and the Massachusetts elements at the same time, and generates a single program that satisfies both, with each clause labeled by the provision it addresses.
Dual mapping
Every clause tagged to 16 CFR 314.4 and to 201 CMR 17.03 or 17.04, so you can produce either view on demand.
The annual review, as a document
17.03(2)(i) requires a review at least annually or on material change. ProtPTX produces it as a dated, signed artifact rather than a calendar alert.
Material change detection
New vendor, new office, new remote worker, new AI tool. Each one is a trigger under 17.03(2)(i), and each one opens an action rather than passing unnoticed.
Run the Massachusetts checklist against your firm
The free assessment covers all ten program elements and all eight computer security controls, alongside the federal requirements. Most firms have never seen this list applied to themselves.