Massachusetts Amendments Impose Additional Data Security Breach Requirements

Locke Lord LLP
Contact

On January 10, 2019, Massachusetts Governor Baker signed “An Act relative to consumer protection from security breaches” (House Bill No. 4806), which added new requirements and obligations for companies that experience a data breach.  The new requirements impose expanded content requirements for breach notices provided to Massachusetts state agencies, including contact and other information for the person reporting the breach of security, identification of the person responsible for the breach, and the types of personal information compromised.

The new law also expands content requirements for breach notifications to affected individuals, including that there is no charge for a security freeze, a description of mitigation services, and the identity of a parent company if the breached company is a subsidiary.  Sample notices to individuals must be filed with the attorney general and with the office of consumer affairs and business regulation, which must post the sample notice on its website.

Breach notices cannot be delayed on the grounds that the total number of affected individuals has not been ascertained.

In addition, in breaches involving Social Security numbers, free credit monitoring services must be offered to affected individuals for at least 18 months; at least 42 months of free services where the breach involves a consumer reporting agency.  Consumers cannot be required to waive rights to sue as a condition of accepting the services.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Locke Lord LLP | Attorney Advertising

Written by:

Locke Lord LLP
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Locke Lord LLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide