On September 22, 2008, the Office of Consumer Affairs and Business Regulation of the Commonwealth of Massachusetts promulgated final regulations regarding the standards to be met by persons or businesses who own, license, store, or maintain personal information about a resident of the Commonwealth. As we reported in our Privacy and Security Alert regarding the Massachusetts Data Breach Notification law, the penalties for noncompliance can be hefty.
The proposed regulations were the subject of a public hearing on January 11, 2008 and were heavily commented upon as being too burdensome and specific. The final regulations address many of the concerns of the commentators and differ from the proposed regulations in the following principal ways:
The full text of the regulations can be found here. Any company with personal information of Massachusetts residents should be aware of and become familiar with the provisions of the regulations in order to prepare for complying with the requirements before the effective date of January 1, 2009.
Endnotes
1 Standards for Insuring the Security, Confidentiality, Integrity and Protection of Customer Records and Information, 16 C.F.R. Part 314.
For assistance in this area,
please contact:
Cynthia Larose, CIPP
(617) 348-1732
CLarose@mintz.com
Elissa Flynn-Poppey
(617) 348-1868
EFlynn-Poppey@mintz.com
Julia M. Siripurapu
(617) 348-3039
JSiripurapu@mintz.com
or any member of your
Mintz Levin client service team.