{
 "jurisdiction_id": "US-MA",
 "jurisdiction": "United States – Massachusetts",
 "url": "https://dataprotection.gi/jurisdictions/united-states-massachusetts/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-06",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 48,
  "sub_modules": 57,
  "source_register": 27
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "red",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-massachusetts/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "No comprehensive omnibus statute is in force; coverage is fragmented across breach-notification, public-sector, and federal sectoral law, consistent with the seed's CRITICAL flag.",
   "claims": [
    {
     "statement": "The Massachusetts Attorney General's office established a standalone Data Privacy and Security Division, joining a minority of states with a dedicated privacy enforcement unit, tasked with investigating and enforcing the state's Consumer Protection Act and Data Breach Law.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/mass-ags-data-privacy-security-division-an-advocate-for-consumers",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Section 5 of the FTC Act bars unfair and deceptive acts or practices in or affecting commerce and is the general federal privacy-enforcement backstop applicable within Massachusetts absent a comprehensive state statute.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Federal Trade Commission",
     "source_url": "https://www.ftc.gov/news-events/topics/protecting-consumer-privacy-security/privacy-security-enforcement",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Massachusetts General Laws Chapter 93H requires organizations to notify the Attorney General and affected residents of a breach of security involving personal information, and the AG's office launched an online portal to accept such notifications.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/massachusetts-ag-launches-online-data-breach-reporting",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "As of the run date, the Massachusetts House and Senate have each passed differing versions of comprehensive consumer data-privacy legislation which had not been reconciled into a single enrolled bill or presented to the Governor for signature.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/massachusetts-house-passes-consumer-data-privacy-bill",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Massachusetts maintains a public-sector Fair Information Practices Act (Chapter 66A) governing state-agency handling of personal data, distinct from any private-sector comprehensive privacy statute.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/legal-research/massachusetts-statutes-part-i-0",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Personal information subject to breach-notification duties in state breach-notification statutes typically includes a resident's name combined with a Social Security number, driver's license number, financial account number, or medical information.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "NAAG",
     "source_url": "https://www.naag.org/wp-content/uploads/2021/02/Powers-and-Duties-4th-Edition-Chapter-13.0-Consumer-Protection-Courtesy-Chapter.pdf",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "In the absence of a comprehensive MA statute, territorial reach over data practices affecting MA residents is supplied by federal sectoral statutes and FTC Section 5 enforcement, which attach based on effects on consumers rather than controller establishment.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "Federal Trade Commission",
     "source_url": "https://www.ftc.gov/news-events/topics/protecting-consumer-privacy-security/privacy-security-enforcement",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Organizations experiencing a qualifying security breach must notify the Massachusetts Attorney General, who provides a voluntary online reporting portal as an alternative to written notice, as required under Chapter 93H.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/massachusetts-ag-launches-online-data-breach-reporting",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "red",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-massachusetts/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Fundamental gap flagged per seed CRITICAL disambiguation — no general lawful-basis or consent-standard statute exists.",
   "claims": [
    {
     "statement": "Massachusetts has no comprehensive consumer-privacy statute establishing enumerated lawful bases for processing personal data outside of sectoral contexts.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "NAAG",
     "source_url": "https://www.naag.org/wp-content/uploads/2021/02/Powers-and-Duties-4th-Edition-Chapter-13.0-Consumer-Protection-Courtesy-Chapter.pdf",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "A pending Senate Bill 220 would require private entities to obtain informed consent before collecting biometric data and to adopt written retention and destruction policies, with statutory damages of at least $5,000 per violation, but the bill has not been enacted.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/massachusetts-legislature-discusses-biometric-privacy",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Attorneys general, including in Massachusetts, enforce privacy protections for sensitive categories of information such as health data primarily through federal statutes including HIPAA, alongside state consumer-protection and breach-notification law.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "NAAG",
     "source_url": "https://www.naag.org/wp-content/uploads/2021/02/Powers-and-Duties-4th-Edition-Chapter-13.0-Consumer-Protection-Courtesy-Chapter.pdf",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "A pending House Bill 127 would define 'de-identified data' for K-12 student-data purposes only, limiting operators' ability to use such data outside narrowly permitted educational purposes; the bill has not been enacted.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/massachusetts-bill-presented-joint-committee-education",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "red",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-massachusetts/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "No comprehensive data-subject-rights framework; only narrow federal-sectoral rights apply.",
   "claims": [
    {
     "statement": "The federal Fair Credit Reporting Act promotes accuracy and fairness in consumer-reporting-agency files and provides consumers limited rights to obtain and review their consumer reports, applicable to Massachusetts residents as part of the national FCRA regime.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Federal Trade Commission",
     "source_url": "https://www.ftc.gov/news-events/topics/consumer-finance/credit-reporting",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The FTC pursues an enforcement program against consumer-reporting agencies and furnishers under the FCRA that includes obligations related to inaccurate information, providing consumers an indirect correction pathway distinct from any general MA erasure right.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "Federal Trade Commission",
     "source_url": "https://www.ftc.gov/news-events/topics/consumer-finance/credit-reporting",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Massachusetts confers no statutory right to data portability for consumer personal information, consistent with the absence of a comprehensive consumer-privacy law.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "NAAG",
     "source_url": "https://www.naag.org/wp-content/uploads/2021/02/Powers-and-Duties-4th-Edition-Chapter-13.0-Consumer-Protection-Courtesy-Chapter.pdf",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Massachusetts' breach-notification statute governs timing of notice to the Attorney General and affected residents following a security breach, though the precise statutory deadline text was not independently retrieved and verified in this research session.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/gdpr-match-up-u-s-state-data-breach-laws",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "amber",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-massachusetts/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Binding security and breach-notification duties exist and are well-established, but broader accountability instruments (DPIA, DPO, ROPA) are absent.",
   "claims": [
    {
     "statement": "Massachusetts has several laws relating to data security and cybersecurity, and covered organisations that own or license personal information are subject to the obligations set forth under those applicable laws rather than a formal GDPR-style DPIA regime.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/massachusetts-cybersecurity",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Massachusetts has no statutory requirement for covered entities to appoint a Data Protection Officer.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "NAAG",
     "source_url": "https://www.naag.org/wp-content/uploads/2021/02/Powers-and-Duties-4th-Edition-Chapter-13.0-Consumer-Protection-Courtesy-Chapter.pdf",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "No Massachusetts-specific records-of-processing-activities obligation was identified outside of sector-level documentation duties such as those under HIPAA.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "NAAG",
     "source_url": "https://www.naag.org/wp-content/uploads/2021/02/Powers-and-Duties-4th-Edition-Chapter-13.0-Consumer-Protection-Courtesy-Chapter.pdf",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Massachusetts data-security law provides that a person or agency complying with an applicable federal or state law offering equivalent or greater protection, such as GLBA or HIPAA safeguard regulations, is treated as satisfying the state's reasonable-security requirement, mirroring similar carve-outs in other states.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/exceptions-in-new-state-privacy-laws-leave-data-without-security-coverage",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The FTC's Safeguards Rule requires financial institutions under FTC jurisdiction, including those operating in Massachusetts, to maintain an information security program with administrative, technical, and physical safeguards to protect customer information.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Federal Trade Commission",
     "source_url": "https://www.ftc.gov/legal-library/browse/rules/safeguards-rule",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Massachusetts General Law Chapter 93H requires notice to the Attorney General and to all potentially affected consumers in the event of a data breach, and the AG's office launched an online portal in 2018 to accept such notifications.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/massachusetts-ag-launches-online-data-breach-reporting",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Unlike states such as California that mandate specific content and format for breach notices, Massachusetts law is distinctive in excluding certain background details about the breach from the required consumer notification.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/gdpr-match-up-u-s-state-data-breach-laws",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Massachusetts data-security regulation obligates covered organisations that own or license personal information to address retention and secure disposal as part of their overall information-security obligations, though the precise disposal-statute citation was not independently confirmed via a retrievable primary source this session.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/massachusetts-cybersecurity",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "amber",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-massachusetts/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "Cross-border transfer coverage exists only via the federal DPF mechanism; no MA-specific transfer rules exist.",
   "claims": [
    {
     "statement": "The European Commission issued an adequacy decision on the EU-U.S. Data Privacy Framework on July 17, 2023, providing a federal-level mechanism by which companies, including those operating in Massachusetts, may self-certify to transfer personal data from the EU to the United States.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Federal Trade Commission",
     "source_url": "https://www.ftc.gov/business-guidance/privacy-security",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-massachusetts/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Strong federal sectoral coverage; MA-specific sectoral overlays are thin or pending.",
   "claims": [
    {
     "statement": "The Gramm-Leach-Bliley Act requires financial institutions to explain their information-sharing practices to customers and to safeguard sensitive data, applicable to financial institutions operating in Massachusetts.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Federal Trade Commission",
     "source_url": "https://www.ftc.gov/business-guidance/privacy-security/gramm-leach-bliley-act",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The FTC Safeguards Rule requires financial institutions under FTC jurisdiction to have measures in place to keep customer information secure, including institutions operating in Massachusetts.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Federal Trade Commission",
     "source_url": "https://www.ftc.gov/legal-library/browse/rules/safeguards-rule",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Attorneys general, including in Massachusetts, work together and rely on HIPAA in addressing healthcare-related privacy violations affecting consumers' medical information.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "NAAG",
     "source_url": "https://www.naag.org/wp-content/uploads/2021/02/Powers-and-Duties-4th-Edition-Chapter-13.0-Consumer-Protection-Courtesy-Chapter.pdf",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Federal telemarketing and consumer-protection law, including the Telephone Consumer Protection Act and the Telemarketing Sales Rule, has been the basis of significant multi-state enforcement actions applicable nationally, in the absence of an MA-specific ePrivacy statute.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "NAAG",
     "source_url": "https://www.naag.org/wp-content/uploads/2021/02/Powers-and-Duties-4th-Edition-Chapter-13.0-Consumer-Protection-Courtesy-Chapter.pdf",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Fair Credit Reporting Act promotes the accuracy, fairness, and privacy of information in consumer-reporting-agency files, and the FTC pursues an active enforcement program against CRAs, furnishers, and users of consumer reports nationally, including Massachusetts.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Federal Trade Commission",
     "source_url": "https://www.ftc.gov/news-events/topics/consumer-finance/credit-reporting",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Pending House Bill 127 would update Massachusetts' K-12 student-data statute by limiting how online service vendors may use, share, sell, or rent student data and by expanding definitions of covered and de-identified information.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/massachusetts-bill-presented-joint-committee-education",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "An NAIC model regulation governs privacy of consumer financial and health information for state-insurance-department licensees, including limits on disclosure of nonpublic personal financial information, but Massachusetts' specific adoption status of this or the NAIC Insurance Data Security Model Law was not independently confirmed this session.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "NAIC (hosted via DataGuidance)",
     "source_url": "https://www.dataguidance.com/sites/default/files/privacy_of_consumer_financial_and_health_information_model_regulation.pdf",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "red",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-massachusetts/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "No comprehensive MA adtech/commercial-privacy statute; coverage is incidental via FTC Section 5 and a pending sector-specific bill.",
   "claims": [
    {
     "statement": "FTC consent orders define 'Affirmative Express Consent' to exclude agreement obtained through user-interface designs manipulated so as to subvert or impair user autonomy, decision-making, or choice, operating as a federal dark-pattern check applicable to companies serving Massachusetts consumers.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Federal Trade Commission",
     "source_url": "https://www.ftc.gov/system/files/ftc_gov/pdf/goodrx_stipulated_order_for_permanent_injunction_civil_penalty_judgment_and_other_relief.pdf",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Pending House Bill 127 would prohibit operators from engaging in targeted advertising based on information acquired through use of a K-12 site, service, or application, though it has not been enacted.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/massachusetts-bill-presented-joint-committee-education",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Multi-state and federal enforcement, such as the action against Dish Network for violations of the Telemarketing Sales Rule and Telephone Consumer Protection Act, illustrates that direct-marketing suppression obligations in Massachusetts arise from federal telemarketing law rather than a dedicated MA direct-marketing statute.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "NAAG",
     "source_url": "https://www.naag.org/wp-content/uploads/2021/02/Powers-and-Duties-4th-Edition-Chapter-13.0-Consumer-Protection-Courtesy-Chapter.pdf",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-massachusetts/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "A binding government-use facial-recognition restriction exists, but private-sector biometric, profiling, and ADM-transparency rules remain absent or pending.",
   "claims": [
    {
     "statement": "The FTC issued a proposed policy statement concerning the suppression of accuracy in artificial intelligence systems in mid-2026, representing federal-level AI-governance activity applicable to companies operating in Massachusetts in the absence of a state AI statute.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "Federal Trade Commission",
     "source_url": "https://www.ftc.gov/news-events/topics/protecting-consumer-privacy-security/privacy-security-enforcement",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Massachusetts Senate Bill 220 would expand definitions of biometric information and identifiers and require private entities holding biometric data to adopt written retention and destruction policies, but the bill remains pending and unenacted.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/massachusetts-legislature-discusses-biometric-privacy",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Massachusetts has banned some police use of facial recognition technology, placing it alongside Virginia among states restricting government surveillance use of the technology.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/maine-passes-statewide-facial-recognition-ban",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-massachusetts/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "Strong federal COPPA coverage; MA-specific K-12 protections remain pending; dependent-adults protections are an unaddressed gap.",
   "claims": [
    {
     "statement": "The FTC issued an Enforcement Policy Statement Promoting the Adoption of Age-Verification Technology on February 25, 2026, a federal-level development applicable to services reaching Massachusetts minors.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "Federal Trade Commission",
     "source_url": "https://www.ftc.gov/news-events/topics/protecting-consumer-privacy-security/privacy-security-enforcement",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The FTC uses the COPPA Rule together with the FTC Act's prohibitions on deceptive and unfair practices to protect children's privacy, including parents' rights to control what data about their children is stored and deleted by covered services.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Federal Trade Commission",
     "source_url": "https://www.ftc.gov/business-guidance/blog/2023/06/hey-alexa-what-are-you-doing-my-data",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Pending House Bill 127 would prevent operators from using information gathered through K-12 educational technology to build a profile of a student, teacher, or administrator except for legitimate educational purposes, but the bill has not been enacted.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/massachusetts-bill-presented-joint-committee-education",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "House Bill 127 was discharged to the Massachusetts Joint Committee on Education in 2021 to update the state's K-12 student-data-privacy statute; its current enactment status was not independently confirmed as final this session.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/massachusetts-bill-presented-joint-committee-education",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "amber",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-massachusetts/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Active federal enforcement (FTC) and a dedicated state AG privacy division exist, but MA-specific 180-day developments are dominated by pending (not enacted) legislation.",
   "claims": [
    {
     "statement": "The Massachusetts Attorney General's Data Privacy and Security Division investigates and enforces the state's Consumer Protection Act and Data Breach Law.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/mass-ags-data-privacy-security-division-an-advocate-for-consumers",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The FTC charges defendants with violating Section 5 of the FTC Act, which bars unfair and deceptive acts and practices in or affecting commerce, as its principal enforcement tool for privacy and data-security matters nationally.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Federal Trade Commission",
     "source_url": "https://www.ftc.gov/news-events/topics/protecting-consumer-privacy-security/privacy-security-enforcement",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "In 2026 the FTC took multiple privacy/data-security enforcement actions of national applicability, including banning Kochava and a subsidiary from selling sensitive location data, an order against Illuminate over failure to secure students' personal data, action against Match and OkCupid for sharing personal data with third parties, and an FCRA action against RentGrow.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Federal Trade Commission",
     "source_url": "https://www.ftc.gov/news-events/topics/protecting-consumer-privacy-security/privacy-security-enforcement",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "In creating a standalone Data Privacy and Security Division, the Massachusetts AG's office joined a minority of states, primarily larger ones, with a dedicated privacy-enforcement unit.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/mass-ags-data-privacy-security-division-an-advocate-for-consumers",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Federal enforcement-comparison literature cites Massachusetts General Laws Chapter 93A Sections 2, 4, and 9 together as the state's consumer-protection framework, consistent with a structure in which Section 4 empowers Attorney General enforcement and Section 9 provides a separate provision commonly associated with consumer civil actions, though this session could not independently confirm Section 9's precise scope for data-privacy claims via primary text.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "Federal Trade Commission",
     "source_url": "https://www.ftc.gov/sites/default/files/documents/public_comments/section-5-workshop-537633-00002/537633-00002.pdf",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Within the 180 days preceding the run date, the Massachusetts House passed a Consumer Data Privacy bill and the Senate had separately passed its own Consumer Data Privacy Act version, without confirmed reconciliation or gubernatorial signature, while federal FTC activity (AI accuracy-suppression policy statement, age-verification enforcement policy, Illuminate and Kochava orders) continued to apply nationally.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/massachusetts-house-passes-consumer-data-privacy-bill",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  }
 ]
}