201 CMR 17.00

Also known as: 201 CMR 17, Massachusetts data security regulation, MA 201 CMR 17.00

201 CMR 17.00 — Standards for the Protection of Personal Information of Residents of the Commonwealth — Massachusetts Office of Consumer Affairs and Business Regulation

The oldest prescriptive state security regulation in the United States: anyone holding personal information about a Massachusetts resident must run a written information security programme, encrypt that data on laptops and in transit, authenticate and limit access to it, and bind third-party service providers by contract to the same standard. Written under MGL c. 93H, and still the template other states borrow from.

Subscribe to 201 CMR 17.00 (RSS)

Timeline

No changes recorded yet — we are watching, and nothing has been published.
1 of 1 behind schedule right now, so this may be incomplete.

Monitoring

Watched by 1 official source.

1 of 1 behind schedule right now — this page may be incomplete.