Law note · Massachusetts

Security Breach statute, duty to report breach of personal information

cite Mass. Gen. Laws ch. 93H, ยง 3 stage IMMINENT commencement not set reviewed 2026-08-28

Massachusetts's Security Breach statute, Mass. Gen. Laws ch. 93H, first enacted 2007, requires a person or agency that owns or licenses data including a resident's personal information to notify the Attorney General, the Director of Consumer Affairs and Business Regulation, and the affected resident as soon as practicable and without unreasonable delay upon learning of a breach of security or unauthorized acquisition or use.

Personal information is a resident's name combined with a Social Security number, driver's license or state ID number, or financial account or card number, and excludes information lawfully obtained from publicly available sources or government records; it does not define or reach biometric data at all.

What it asks of an app

  • Notify the Massachusetts Attorney General, the Director of Consumer Affairs and Business Regulation, and each affected Massachusetts resident as soon as practicable and without unreasonable delay after learning of a breach of security involving personal information.
  • Do not rely on ch. 93H to cover a breach exposing only biometric data; its personal information definition does not reach biometric identifiers at all.

When LexLint raises it

Declared activities: crawls_web, trains_models, deploys_chatbot, automated_outreach

Primary source: official Massachusetts General Laws text, Massachusetts Legislature

← Back to the example  ·  Lint your app →