The following is not meant to be legal advice.
Massachusetts enacted a data protection law that governs the security and disposal of personal information of Massachusetts residents. This law, Chapter 93H, became effective on October 31, 2007. This law impacts any company that collects, maintains, or owns personal information data on Massachusetts residents without regard to the location of the company’s place of business.
The law requires notification to residents and state authorities if personal information (such as name, credit card number, or social security number) is improperly accessed or used. Chapter 93I requires destruction of hard copy and electronic data containing personal information of Massachusetts residents beginning on February 3, 2008.
The Massachusetts law requires companies and employers to send notifications of data security breaches concerning personal information in both electronic and hard copy form. The notices have to be sent to the Massachusetts residents, as well as two state authorities.
Companies doing business in Massachusetts might consider implementing an information security program, including internal policies and procedures on the handling of personal information; and monitor employee data security training on records, data access and storage, and information systems.

Comment Preview