[Blog](/blog)

Show links

Resources

[Blog](/blog)

[Breaches](/breaches)

[eBooks, reports, & more](/resources)

[Events](/events)

[News](/news)

[Compliance and Regulations](/category/compliance-and-regulations)

Show links

Categories

[Attack Surface Management](/category/attack-surface-management)

[Company News](/category/company-news)

[Compliance and Regulations](/category/compliance-and-regulations)

[Cybersecurity](/category/cybersecurity)

[Data Breaches](/category/data-breaches)

[DevOps](/category/devops)

[Human Cyber Risk](/category/human-cyber-risk)

[Risks and Vulnerabilities](/category/risks-and-vulnerabilities)

[Third-Party Risk Management](/category/third-party-risk-management)

[Vendor Risk Management](/category/vendor-risk-management)

[What is the Massachusetts Data Security Law? Guide + Tips](/blog/mass-data-security-law)

Publish date

January 16, 2025

{x} minute read

# What is the Massachusetts Data Security Law? Guide + Tips

[Get a demo](/contact-sales)

[Free trial](/demo)

[Download the PDF guide](/resources/complete-guide-to-data-breaches)

[Free trial](/demo)

Written by

[Nicholas Sollitto](/team/nicholas-sollitto)

Senior Cybersecurity Writer

Nicholas's cybersecurity writing has been featured in G2.

Reviewed by

[Kaushik Sen](/team/kaushik-sen)

Chief Marketing Officer

Kaushik has a background in software engineering, enterprise solution architecture, and data analytics. He brings a unique, data-driven perspective to cybersecurity education.

Table of contents

eBook

A Complete Guide to Data Breaches

Free resource

### A Complete Guide to Data Breaches

Learn how to avoid a costly data breach with a comprehensive prevention strategy.

[Download now](/resources/complete-guide-to-data-breaches)

The Massachusetts Data Security Law (201 CMR 17.00) safeguards the[ personal information](https://www.upguard.com/blog/personally-identifiable-information-pii) of Massachusetts residents. The law went into effect on March 1, 2010, and at the time, was one of the most[ comprehensive data privacy laws](https://iapp.org/resources/article/us-state-privacy-legislation-tracker/) passed in the United States.

Since the law’s passing, a variety of U.S. States have passed more robust data privacy legislation, including the notable[ California Consumer Privacy Act (CCPA)](https://www.upguard.com/blog/what-is-the-ccpa) and[ Virginia Consumer Data Privacy Act (VCDPA)](https://www.upguard.com/blog/vcdpa). In many ways, Massachusetts’ early[ data security](https://www.upguard.com/blog/data-security) law was a precursor to these widely influential laws.

In early 2022, Massachusetts began work to pass an updated and more strict data privacy act named the Massachusetts Information Privacy and Security Act (MIPSA). The state government moved the new law to the state committee on[ Senate Ways and Means](https://malegislature.gov/Bills/192/S2687) on January 3, 2023.

[Discover how UpGuard’s comprehensive cybersecurity solution empowers organizations to achieve compliance across their supply chain >](https://www.upguard.com/product/vendorrisk)

## What Are the Objectives of the Massachusetts Data Security Law?

Massachusetts passed statute 201 CMR 17.00 to establish standards for the protection of personal information of residents:

The law possesses three main objectives to defend residents of the Commonwealth:

* Ensure the confidentiality of personal information
* Protect the integrity and security of personal information
* Protect personal information from unauthorized access

The law places strict [compliance regulations](https://www.upguard.com/blog/what-is-compliance-management) and data privacy obligations on data controllers and processors to achieve these three objectives.

## Who Must Comply With 201 CMR 17.00?

The Massachusetts Data Security Law requires compliance from many organizations, including any business that receives, stores, or otherwise processes the personal information of Massachusetts residents in connection with the sale of goods or services. The law also regulates companies that obtain personal information in an employment context.

*Note:* The scope of 201 CMR 17.00 extends to businesses operating in Massachusetts and those outside the state that process the personal information of Massachusetts residents.

## What is Personal Information?

Massachusetts law 201 CMR 17.00 defines personal information as any piece of information that includes a person’s first and last name (or first initial and last name) and any one of the following:

* Social security number
* Driver’s license number or state-issued identification number

- Financial account number (bank account, credit or debit card, etc.)

Under the law, personal information does not include any information lawfully obtained from public, state, or federal government records. The law also excludes information that is explicitly considered public knowledge.

According to Massachusetts law, businesses that only use credit card swiping technology and batch out data per state and federal standards do not own or license personal information. 

*Note:* The definition of personal information used by 201 CMR 17.00 comes from Massachusetts General Law (M.G.L) Chapter 93H. Other privacy laws around the United States have stricter definitions of public information. Businesses should be careful when considering if they qualify for an exemption from any data privacy law, for they may be required to comply with another overlapping law.

## Requirements of the Massachusetts Data Security Law (201 CMR 17.00)

The standards set forth by 201 CMR 17.00 require organizations that collect or process the personal information of Massachusetts residents to:

* Develop a written information security program (WISP) that includes a computer security system
* Designate at least one employee to maintain the WISP and its security policies
* Conduct[ risk assessments](https://www.upguard.com/product/risk-assessments) and install improvements to safeguard personal data
* Take disciplinary measures and reasonable steps to penalize employees who violate the WISP
* Develop[ security measures](https://www.upguard.com/blog/vulnerability-management) to improve the data protection of personal information
* Document any breach of security or[ data leak](https://www.upguard.com/blog/data-leak) and the process that the organization took to respond to such events

*Note:* Safeguards included within an organization’s WISP must be consistent with other state or federal regulations the organization is subject to ([HIPAA](https://www.upguard.com/blog/hipaa-privacy-rule),[ GLBA](https://www.upguard.com/blog/glba),[ FERPA](https://www.upguard.com/blog/ferpa-compliance-guide), etc.). In other words, small businesses that do not process large amounts of protected information are not subject to the exact requirements as entities with a more considerable amount of resources.

## Computer System Security Requirements

Massachusetts regulations command businesses to fortify their computer security system with industry standards for data privacy when technically feasible.

These standards must include:

* Control of all user identifiers and passwords for authentication purposes
* Strict lock-out procedures for inactive users or failed log-in attempts
* Access limitations or controls for persons who are reasonably required to interact with personal data or such information
* Up-to-date firewall protection and operating system to prevent data breaches
* Security patches for systems connected to the Internet
* Up-to-date versions of system security agent software (malware protection and virus definitions)
* Encryption protocols to anonymize any personal information that an organization shares over a public network
* Employee[ education and training](https://www.upguard.com/blog/developing-a-culture-of-cybersecurity) protocols

## Encryption Protocols Under 201 CMR 17.00

Encryption is the most significant protocol required by the Massachusetts Data Security Law. Under the law, organizations must encrypt all records or files that will or will likely be transmitted wirelessly or across a public network. Organizations must also encrypt all personal data stored on a laptop or portable device.

Unlike some other privacy laws, Massachusetts requires ALL personal information to be encrypted even if storage devices do not leave business premises.

### Definition of Encrypted (201 CMR 17.00)

Massachusetts law defines encryption as transforming data into a form that cannot be reasonably assigned to an individual without using a key or password. The organization must also alter the data into an unreadable format to meet the standards of the law. Password protection alone does not equal compliance.

Businesses must also consider ways to prevent [identity theft](https://www.upguard.com/blog/identity-theft). Under the law’s reasonable standard of care, personal data should not be communicated by unprotected means, such as email or SMS.

## Contracts Between Businesses and Third-Party Service Providers

Under the law, all service providers must sign a contract that obligates them to comply with the Massachusetts Data Security Law standards. Organizations must also do their due diligence when selecting third-party vendors to assist their businesses.

## Enforcement of 201 CMR 17.00

The Massachusetts Data Security Law appoints the Massachusetts Attorney General to carry out all enforcement action. The Attorney General’s office will notify any entity that violates the law and enforce a strict compliance deadline. Businesses that do not comply after being notified of a violation of the law will likely incur civil penalties of up to $5,000 per affected individual.

## How Can UpGuard Help?

[UpGuard’s Vendor Risk](https://www.upguard.com/product/vendorrisk) product empowers organizations to achieve compliance (201 CMR 17.00, MHMDA,[ VCDPA](https://www.upguard.com/blog/vcdpa),[ CCPA](https://www.upguard.com/blog/what-is-the-ccpa),[ GDPR](https://www.upguard.com/blog/how-to-be-gdpr-compliant), etc.)across their supply chain. The technology also allows organizations to automate[ vendor compliance risk assessments](https://www.upguard.com/blog/what-is-compliance-management) and receive real-time updates to their[ security posture](https://www.upguard.com/blog/security-posture).

[UpGuard’s Breach Risk](https://www.upguard.com/product/breachsight) enables organizations to take complete control over their data-handling program. The product allows businesses to proactively monitor their[ attack surface](https://www.upguard.com/blog/attack-surface), gain confidence in their[ cybersecurity](https://www.upguard.com/blog/biometrics) protections, and establish best practices in line with 201 CMR 17.00 or any other compliance regulation.

*Note:* Organizations can read additional Massachusetts Data Security Law information on[ Mass.gov](https://www.mass.gov/regulations/201-CMR-1700-standards-for-the-protection-of-personal-information-of-ma-residents). The Commonwealth of Massachusetts Office of Consumer Affairs and Business Regulation (OCABR) has also published several[ FAQs](https://www.mass.gov/doc/frequently-asked-questions-regarding-201-cmr-1700) on the subject.

eBook

A Complete Guide to Data Breaches

Free resource

### A Complete Guide to Data Breaches

Learn how to avoid a costly data breach with a comprehensive prevention strategy.

[Download now](/resources/complete-guide-to-data-breaches)

## Related posts

Learn more about the latest issues in cybersecurity.

Compliance and Regulations

#### [Cyber Resilience Act Preparedness: Who's Ready, and Who Can't Be Reached](/blog/cyber-resilience-act-preparedness-whos-ready-and-who-cant-be-reached)

We surveyed 2,374 EU-registered devices and 226 listed software makers for a way to report a vulnerability. Market leaders are ready. Others, not so much.

[](/team/greg-pollock)

[Greg Pollock](#)

September 9, 2026

Human Cyber Risk

#### [AI Assurance: The Third Head of Your AI Governance Watchdog](/blog/ai-governance-to-ai-assurance)

AI governance needs three things: policy, enforcement, and assurance. Most organizations have built the first two. Here's why the third one matters now.

[](/team/shane-moosa)

[Shane Moosa](#)

September 21, 2026

Compliance and Regulations

#### [NIST compliance in 2026: A complete implementation guide](/blog/nist-compliance)

NIST compliance ensures alignment with leading cybersecurity frameworks. Explore how the NIST standards can safeguard sensitive data and manage third-party

[](/team/edward-kost)

[Edward Kost](#)

January 5, 2026

Compliance and Regulations

#### [Introducing UpGuard’s DPDP Act Security Questionnaire](/blog/upguards-dpdp-security-questionnaire)

Discover the latest addition to UpGuard's industry-leading Questionnaire Library and learn how to achieve comprehensive DPDP compliance.

[](/team/nicholas-sollitto)

[Nicholas Sollitto](#)

November 19, 2024

Compliance and Regulations

#### [From NIS to NIS2: What Your Organization Needs to Know](/blog/nis-vs-nis2)

Understanding the transition from NIS to NIS2 is crucial for protecting your organization. Explore the key changes and compliance steps in this blog.

[](/team/leah-sadoian)

[Leah Sadoian](#)

July 4, 2025

Compliance and Regulations

#### [How to Prepare for a Cyber Essentials Plus Audit](/blog/prepare-for-a-cyber-essentials-plus-audit)

Learn more about the Cyber Essentials Plus independent assessment process, and steps your organization can take to prepare.

[](/team/leah-sadoian)

[Leah Sadoian](#)

July 3, 2025

[All posts](/blog)

Experience superior visibility and a simpler approach to cyber risk management

[Get a demo](/contact-sales)

[Free trial](/demo)
