The Office of Consumer Affairs and Business Regulation, pursuant to the authority granted to it by G.L. c. 93H, in November 2009 promulgated 201 CMR 17:00, a regulation setting standards for the protection of personal information of Massachusetts residents. The Division of Standards reminds all of its licensees about their obligations under this regulation and the March 1, 2010 deadline for full compliance.
Any person that receives, stores, maintains, processes or otherwise has access to personal information acquired in connection with employment or with the provision of goods or services to a Massachusetts resident has a duty to protect that information. A "person," for purposes of the regulation, may be an individual, corporation, association, partnership or other legal entity. Personal information includes a surname, together with a first name or initial, in combination with one or more of the following three data elements pertaining to that person: Social Security Number; driver's license or state-issued identification card number; or financial account or credit or debit card number, with or without any other data element, such as a code, password, or PIN, that would permit access to the person's financial account.
The duty includes the requirement that the person develops and maintain a comprehensive written information security program ("WISP") to safeguard such information. If the person electronically stores or transmits personal information, the WISP must include a security system covering the person's computers and any portable and/or wireless devices. (More Info)