Law note · Massachusetts
Consumer Protection General Regulations, deeming a data-security violation an unfair practice
A private right of action for a Massachusetts data-security violation opens through a separate Attorney General consumer-protection regulation, not through ch. 93H or 201 CMR 17.00 directly.
940 CMR 3.16, promulgated under ch. 93A section 2(c), provides that an act or practice violates ch. 93A section 2 if, among other things, it fails to comply with an existing statute, rule, or regulation meant for the protection of the public's health, safety, or welfare and intended to provide Massachusetts consumers protection.
A failure to comply with ch. 93H's breach-notice duty or 201 CMR 17.00's WISP mandate is therefore a ch. 93A section 2 violation, which ch. 93A section 9 arms any injured person to sue on for damages, trebled if the violation was knowing, plus attorney fees. Chapter 93H section 6 alone does not open this route; the mechanism is entirely this separate regulation.
What it asks of an app
- Comply with ch. 93H's breach-notice duty and 201 CMR 17.00's information security program mandate. Noncompliance with either is a ch. 93A section 2 unfair or deceptive practice under 940 CMR 3.16(3), and any injured person may sue for damages, trebled if knowing, plus attorney fees, under ch. 93A section 9.
When LexLint raises it
Declared activities: crawls_web, trains_models, deploys_chatbot, automated_outreach
Primary source: official Code of Massachusetts Regulations text, Office of the Attorney General, PDF from mass.gov