Law note · Massachusetts

Standards for the Protection of Personal Information of Residents of the Commonwealth

cite 201 CMR 17.01-17.05 stage IMMINENT commencement not set reviewed 2026-08-28

201 CMR 17.00, promulgated by the Office of Consumer Affairs and Business Regulation under authority ch. 93H section 2 grants it, requires every covered person to develop, implement, and maintain a comprehensive written information security program (WISP) with administrative, technical, and physical safeguards, including employee training, service-provider oversight, disciplinary measures, physical access restrictions, and annual review.

This is a proactive security-program mandate, distinct from ch. 93H's reactive breach-notice duty; its own compliance-deadline provision (17.05) is long past. Neither this regulation's definition of personal information, read from the official PDF text, nor ch. 93H's own definition contains the word biometric anywhere.

What it asks of an app

  • Develop, implement, and maintain a comprehensive written information security program (WISP) covering personal information about a Massachusetts resident, with administrative, technical, and physical safeguards including employee training, service-provider oversight, and physical access restrictions.
  • Review your WISP at least annually.
  • Do not rely on 201 CMR 17.00 to cover biometric data; its personal information definition, like ch. 93H's, does not reach biometric identifiers.

When LexLint raises it

Declared activities: crawls_web, trains_models, deploys_chatbot, automated_outreach

Primary source: official Code of Massachusetts Regulations text, Office of Consumer Affairs and Business Regulation, PDF from mass.gov

← Back to the example  ·  Lint your app →