We recently informed you that Massachusetts enacted comprehensive data security regulations relating to a 2007 data security law intended to protect Massachusetts residents from identity theft. A copy of the bulleting explaining the regulations can be found here. These regulations, which had been slated to take effect on January 1, 2009, will impose a significant compliance obligation on virtually all businesses with employees or customers in Massachusetts. In light of current economic conditions, the general deadline for compliance with Massachusetts' data security regulations has been extended to May 1, 2009, while the deadline for obtaining written certification of security compliance from third party providers, and for encrypting portable devices other than laptops, has been extended to January 1, 2010.

Foley Hoag is holding a seminar at its Boston office regarding the law and its regulations on December 10, 2008, beginning at 7:30 a.m. Click here for more information.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.