ARTICLE
1 February 2019

Massachusetts Changes Data Breach Notification Requirements

SM
Sheppard Mullin Richter & Hampton

Contributor

Sheppard Mullin is a full service Global 100 firm with over 1,000 attorneys in 16 offices located in the United States, Europe and Asia. Since 1927, companies have turned to Sheppard Mullin to handle corporate and technology matters, high stakes litigation and complex financial transactions. In the US, the firm’s clients include more than half of the Fortune 100.
The Governor of Massachusetts has just signed into law amendments to the state's data breach notification law.
United States Privacy

The Governor of Massachusetts has just signed into law  amendments to the state's data breach notification law. The amendments will go into effect April 11, 2019. Under the amended law, companies whose breaches involve Social Security numbers must provide free credit monitoring services to affected individuals. The services must last 18 months (42 months if the breached company is a credit reporting agency). Companies can't require individuals to waive their rights to sue in order to get free credit monitoring and must certify to the state that the services provided comply with the law.

The amended law includes new requirements for consumer breach notices. Those notices must now describe any required credit monitoring services and identify a breached company's parent company if it has one. A company won't be able to delay sending notices while it identifies all affected consumers, but must send notices on a rolling basis. The amended law also requires more information in notices to state regulators. Breach notices to the two state regulators must now identify the person responsible for the breach (if it is known), the person reporting the breach, and the types of personal information compromised. Notices must also describe the steps taken by the company after the breach—including whether the company has revised its written information security program.

Putting it Into Practice: Companies with a nationwide incident response plan should keep in mind this expanded (18) month credit monitoring requirement.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More