Law / Massachusetts

Massachusetts

age

Massachusetts has not yet enacted an age-gating statute, but both chambers of the legislature passed distinct social media bills for minors in 2026 that must be reconciled before either can reach the Governor.

The House passed its version on April 8, 2026 by substituting the text of H.5349 into S.2581, a Senate passed school cellphone bill; it would bar platforms from allowing accounts for users under 14 and would require verifiable parental consent for 14 and 15 year olds, using the best available age verification technology. The Senate non-concurred and a conference committee was appointed in May 2026.

The Senate separately passed S.3164 on July 9, 2026, which would instead require platforms to disable addictive design features, such as autoplay, infinite scroll, and algorithmic feeds, by default for minors, using an age verification method that need not rely solely on government ID. No adult content or app store age verification bill has advanced in Massachusetts.

privacy

Massachusetts has no comprehensive consumer-privacy statute in force. The Massachusetts Data Privacy Act (MDPA), which would establish one, passed the Senate 40-0 as S.2608/S.2619 and the House 146-0 in an amended form (H.5472, republished as H.5479), but the Senate non-concurred in the House amendment on June 11, 2026 and the bill remains in a conference committee with no compromise text produced. Massachusetts's in-force privacy law is a security-breach statute, Mass.

Gen. Laws ch. 93H, and its implementing regulation, 201 CMR 17.00, neither of which defines or reaches biometric data at all; genetic information is protected only as an employment-discrimination category under ch. 151B, not as a data-processing right.

Chapter 93H's own enforcement clause arms only the Attorney General, but a private right of action for a ch. 93H or 201 CMR 17.00 violation opens through a separate, third instrument: 940 CMR 3.16(3), an Attorney General consumer-protection regulation issued under ch. 93A's own rulemaking power, deems a failure to comply with a consumer-protection statute or regulation an unfair or deceptive act under ch. 93A section 2, which ch. 93A section 9 then arms a private plaintiff to sue on for damages, trebled if knowing, plus attorney fees.

17 instruments named 8 researched in detail As of 2026-08-28

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Breach notification

Security Breach statute, credit monitoring offer required

cite Mass. Gen. Laws ch. 93H, § 3A stage IMMINENT commencement not set source official Massachusetts General Laws text, Massachusetts Legislature

If a resident's Social Security number was disclosed or reasonably believed disclosed in a breach, the person or agency that experienced the breach must contract with a third party to offer that resident credit monitoring services at no cost for not less than 18 months. If the entity that experienced the breach is itself a consumer reporting agency, it must instead offer not less than 42 months of free credit monitoring.

The entity may not require a resident to waive any right to a private right of action as a condition of the credit-monitoring offer.

What it asks of an app

Security Breach statute, duty to report breach of personal information

cite Mass. Gen. Laws ch. 93H, § 3 stage IMMINENT commencement not set source official Massachusetts General Laws text, Massachusetts Legislature

Massachusetts's Security Breach statute, Mass. Gen. Laws ch. 93H, first enacted 2007, requires a person or agency that owns or licenses data including a resident's personal information to notify the Attorney General, the Director of Consumer Affairs and Business Regulation, and the affected resident as soon as practicable and without unreasonable delay upon learning of a breach of security or unauthorized acquisition or use.

Personal information is a resident's name combined with a Social Security number, driver's license or state ID number, or financial account or card number, and excludes information lawfully obtained from publicly available sources or government records; it does not define or reach biometric data at all.

What it asks of an app

Standards for the Protection of Personal Information of Residents of the Commonwealth

cite 201 CMR 17.01-17.05 stage IMMINENT commencement not set source official Code of Massachusetts Regulations text, Office of Consumer Affairs and Business Regulation, PDF from mass.gov

201 CMR 17.00, promulgated by the Office of Consumer Affairs and Business Regulation under authority ch. 93H section 2 grants it, requires every covered person to develop, implement, and maintain a comprehensive written information security program (WISP) with administrative, technical, and physical safeguards, including employee training, service-provider oversight, disciplinary measures, physical access restrictions, and annual review.

This is a proactive security-program mandate, distinct from ch. 93H's reactive breach-notice duty; its own compliance-deadline provision (17.05) is long past. Neither this regulation's definition of personal information, read from the official PDF text, nor ch. 93H's own definition contains the word biometric anywhere.

What it asks of an app

Comprehensive regime

Massachusetts Data Privacy Act (MDPA)

cite Mass. S.2619 (formerly S.2608); House substitute H.5472/H.5479, 194th Gen. Ct. stage PROPOSED draft date not recorded source official Massachusetts Legislature bill history, malegislature.gov

The Massachusetts Data Privacy Act (MDPA) would establish the state's first comprehensive consumer personal-data regime; it is not enacted and imposes no duty today. Originally S.2608, it passed the Senate 40-0 on September 25, 2025, was engrossed as S.2619, and was amended by the House (Ways and Means reported a substitute striking the text and inserting H.5472, itself amended and republished as H.5479) before passing the House 146-0 on June 4, 2026.

The Senate non-concurred in the House amendment on June 11, 2026 and appointed a conference committee; the House insisted on its own amendment and appointed its own conferees on June 17, 2026. As of this research, the bill remains in conference with no compromise text produced.

What it asks of an app

Enforcement supervision

Consumer Protection General Regulations, deeming a data-security violation an unfair practice

cite 940 CMR 3.16(3); Mass. Gen. Laws ch. 93A, §§ 2, 9 stage IMMINENT commencement not set source official Code of Massachusetts Regulations text, Office of the Attorney General, PDF from mass.gov

A private right of action for a Massachusetts data-security violation opens through a separate Attorney General consumer-protection regulation, not through ch. 93H or 201 CMR 17.00 directly.

940 CMR 3.16, promulgated under ch. 93A section 2(c), provides that an act or practice violates ch. 93A section 2 if, among other things, it fails to comply with an existing statute, rule, or regulation meant for the protection of the public's health, safety, or welfare and intended to provide Massachusetts consumers protection.

A failure to comply with ch. 93H's breach-notice duty or 201 CMR 17.00's WISP mandate is therefore a ch. 93A section 2 violation, which ch. 93A section 9 arms any injured person to sue on for damages, trebled if the violation was knowing, plus attorney fees. Chapter 93H section 6 alone does not open this route; the mechanism is entirely this separate regulation.

What it asks of an app

Security Breach statute, Attorney General enforcement

cite Mass. Gen. Laws ch. 93H, § 6 stage IMMINENT commencement not set source official Massachusetts General Laws text, Massachusetts Legislature

Chapter 93H's own enforcement clause lets the Attorney General bring an action under ch. 93A section 4 to remedy a violation. On its own face, this section creates no private right of action: it does not deem a ch. 93H violation to be an unfair or deceptive practice actionable by a private plaintiff under ch. 93A section 9.

A private right of action for a ch. 93H violation exists only through a separate Attorney General regulation, 940 CMR 3.16(3), recorded as its own instrument in this document.

What it asks of an app

Social media and minors

S.2581 as amended by the House (text of H.5349), An Act to promote student learning and mental health

cite Senate Bill No. 2581, 194th General Court, as amended by the House with the text of House Bill No. 5349 stage PROPOSED draft date not recorded source official bill history and House press release, Massachusetts Legislature

As passed by the House, would bar social media platforms from allowing an account for a user under 14, require termination and deletion of existing under-14 accounts by October 1, 2026, and require verifiable parental consent for 14 and 15 year old users, verified through the best available age verification technology, alongside a school day cellphone ban.

The House engrossed it 129 to 25 on April 8, 2026 by substituting the text of H.5349; the Senate non-concurred on May 7, 2026 and the bill is in a six member conference committee.

Note and primary source

S.3164 (2026), An Act protecting children from addictive social media feeds

cite Senate Bill No. 3164, 194th General Court stage PROPOSED draft date not recorded source official bill text and Senate press release, Massachusetts Legislature

Would require social media platforms to disable, by default, algorithmic feeds, autoplay, infinite scroll, and other addictive design features on minors' accounts, send reminders after extended use, and turn off notifications overnight. Requires an age verification method that need not rely solely on government issued identification. Passed the Senate 38 to 2 on July 9, 2026, and is now before the House, which took a different under-14 ban approach in its own bill.

Note and primary source

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.