Law note · Massachusetts
Security Breach statute, duty to report breach of personal information
Massachusetts's Security Breach statute, Mass. Gen. Laws ch. 93H, first enacted 2007, requires a person or agency that owns or licenses data including a resident's personal information to notify the Attorney General, the Director of Consumer Affairs and Business Regulation, and the affected resident as soon as practicable and without unreasonable delay upon learning of a breach of security or unauthorized acquisition or use.
Personal information is a resident's name combined with a Social Security number, driver's license or state ID number, or financial account or card number, and excludes information lawfully obtained from publicly available sources or government records; it does not define or reach biometric data at all.
What it asks of an app
- Notify the Massachusetts Attorney General, the Director of Consumer Affairs and Business Regulation, and each affected Massachusetts resident as soon as practicable and without unreasonable delay after learning of a breach of security involving personal information.
- Do not rely on ch. 93H to cover a breach exposing only biometric data; its personal information definition does not reach biometric identifiers at all.
When LexLint raises it
Declared activities: crawls_web, trains_models, deploys_chatbot, automated_outreach
Primary source: official Massachusetts General Laws text, Massachusetts Legislature