No comprehensive omnibus statute is in force; coverage is fragmented across breach-notification, public-sector, and federal sectoral law, consistent with the seed's CRITICAL flag.
Primary frameworkMassachusetts General Laws Chapter 93H (data breach notification) and 201 CMR 17.00 (data security regulation), overlaid by federal FTC Act Section 5 and sectoral statutes
Traffic-light rationale — RedNo comprehensive omnibus statute is in force; coverage is fragmented across breach-notification, public-sector, and federal sectoral law, consistent with the seed's CRITICAL flag.
Sub-modules (5)
Regulator And AuthorityAmber
The Massachusetts AG's office maintains a dedicated Data Privacy and Security Division enforcing the Consumer Protection Act and the Data Breach Law.
Claims (1):
The Massachusetts Attorney General's office established a standalone Data Privacy and Security Division, joining a minority of states with a dedicated privacy enforcement unit, tasked with investigating and enforcing the state's Consumer Protection Act and Data Breach Law.
Act And InstrumentsRed
Chapter 93H (breach notification), 201 CMR 17.00 (security standards), Chapter 66A (public-sector FIPA), and Chapter 93A (consumer protection) form the state-law backbone; FTC Act Section 5 is the federal backstop; comprehensive privacy bills remain pending.
Claims (4):
Section 5 of the FTC Act bars unfair and deceptive acts or practices in or affecting commerce and is the general federal privacy-enforcement backstop applicable within Massachusetts absent a comprehensive state statute.
Massachusetts General Laws Chapter 93H requires organizations to notify the Attorney General and affected residents of a breach of security involving personal information, and the AG's office launched an online portal to accept such notifications.
As of the run date, the Massachusetts House and Senate have each passed differing versions of comprehensive consumer data-privacy legislation which had not been reconciled into a single enrolled bill or presented to the Governor for signature.
Massachusetts maintains a public-sector Fair Information Practices Act (Chapter 66A) governing state-agency handling of personal data, distinct from any private-sector comprehensive privacy statute.
Material ScopeAmber
Material scope is defined breach-by-breach via Chapter 93H's definition of 'personal information' rather than by a general GDPR-style material-scope test.
Claims (1):
Personal information subject to breach-notification duties in state breach-notification statutes typically includes a resident's name combined with a Social Security number, driver's license number, financial account number, or medical information.
Territorial ScopeAmber
No MA-specific territorial-scope test exists; applicability is driven by federal sectoral law and FTC Section 5, which reach conduct affecting MA consumers regardless of controller location.
Claims (1):
In the absence of a comprehensive MA statute, territorial reach over data practices affecting MA residents is supplied by federal sectoral statutes and FTC Section 5 enforcement, which attach based on effects on consumers rather than controller establishment.
Regulator Registration And FilingAmber
No general controller-registration regime; the only filing obligation is breach notification to the AG via Chapter 93H, supported by an online reporting portal.
Claims (1):
Organizations experiencing a qualifying security breach must notify the Massachusetts Attorney General, who provides a voluntary online reporting portal as an alternative to written notice, as required under Chapter 93H.
Category narrative122 words
Massachusetts has no comprehensive consumer-privacy statute analogous to GDPR/CCPA. The operative regime is a patchwork: (1) the Massachusetts Attorney General's general consumer-protection authority under Chapter 93A, (2) the state's data-breach-notification statute (Chapter 93H) and its implementing data-security regulation (201 CMR 17.00), (3) a public-sector Fair Information Practices Act (Chapter 66A) applicable to state agencies, and (4) federal sectoral overlays (FTC Act Section 5, HIPAA, GLBA, COPPA, FCRA) that apply nationally including in Massachusetts. Comprehensive consumer-privacy bills (e.g., the Massachusetts Information Privacy Act, the Massachusetts Data Privacy Protection Act, and a 2025-2026 Consumer Data Privacy Act) have been introduced and have passed one or both chambers in different forms but have not been reconciled or signed into law as of the run date.
Sources and claims (8)
ProbableIAPP — The Massachusetts Attorney General's office established a standalone Data Privacy and Security Division, joining a minority of states with a dedicated privacy enforcement unit, tasked with investigating and enforcing the state's Consumer Protection Act and Data Breach Law.observed
ConfirmedFederal Trade Commission — Section 5 of the FTC Act bars unfair and deceptive acts or practices in or affecting commerce and is the general federal privacy-enforcement backstop applicable within Massachusetts absent a comprehensive state statute.observed
ConfirmedOneTrust DataGuidance — Massachusetts General Laws Chapter 93H requires organizations to notify the Attorney General and affected residents of a breach of security involving personal information, and the AG's office launched an online portal to accept such notifications.observed
UncertainOneTrust DataGuidance — As of the run date, the Massachusetts House and Senate have each passed differing versions of comprehensive consumer data-privacy legislation which had not been reconciled into a single enrolled bill or presented to the Governor for signature.observed
UncertainOneTrust DataGuidance — Massachusetts maintains a public-sector Fair Information Practices Act (Chapter 66A) governing state-agency handling of personal data, distinct from any private-sector comprehensive privacy statute.observed
ProbableNAAG — Personal information subject to breach-notification duties in state breach-notification statutes typically includes a resident's name combined with a Social Security number, driver's license number, financial account number, or medical information.observed
ProbableFederal Trade Commission — In the absence of a comprehensive MA statute, territorial reach over data practices affecting MA residents is supplied by federal sectoral statutes and FTC Section 5 enforcement, which attach based on effects on consumers rather than controller establishment.observed
ConfirmedOneTrust DataGuidance — Organizations experiencing a qualifying security breach must notify the Massachusetts Attorney General, who provides a voluntary online reporting portal as an alternative to written notice, as required under Chapter 93H.observed
Traffic-light rationale — RedFundamental gap flagged per seed CRITICAL disambiguation — no general lawful-basis or consent-standard statute exists.
Sub-modules (4)
Lawful BasesRed
No MA statutory analogue to GDPR Art. 6 exists for general commercial processing.
Claims (1):
Massachusetts has no comprehensive consumer-privacy statute establishing enumerated lawful bases for processing personal data outside of sectoral contexts.
Consent ThresholdsRed
No general consent standard; a pending biometric bill would introduce informed-consent requirements for biometric data specifically.
Claims (1):
A pending Senate Bill 220 would require private entities to obtain informed consent before collecting biometric data and to adopt written retention and destruction policies, with statutory damages of at least $5,000 per violation, but the bill has not been enacted.
Special CategoriesAmber
Special-category-type data (health) is addressed only via the federal HIPAA framework, which applies within Massachusetts as it does nationally.
Claims (1):
Attorneys general, including in Massachusetts, enforce privacy protections for sensitive categories of information such as health data primarily through federal statutes including HIPAA, alongside state consumer-protection and breach-notification law.
Pseudonymisation And AnonymisationRed
No general statutory definition; a narrow 'de-identified data' definition appears only in a pending K-12 student-data bill (HB 127).
Claims (1):
A pending House Bill 127 would define 'de-identified data' for K-12 student-data purposes only, limiting operators' ability to use such data outside narrowly permitted educational purposes; the bill has not been enacted.
Category narrative62 words
Massachusetts has no general lawful-basis, consent, or special-category regime akin to GDPR Art. 6/7/9. Coverage is limited to sector contexts: HIPAA governs health information at the federal level; a proposed biometric-data bill (SB 220) would impose informed-consent and retention requirements but has not been enacted; no MA-specific pseudonymisation/anonymisation safe-harbour exists outside a narrow K-12 'de-identified data' definition in a pending student-privacy bill.
Sources and claims (4)
ConfirmedNAAG — Massachusetts has no comprehensive consumer-privacy statute establishing enumerated lawful bases for processing personal data outside of sectoral contexts.observed
UncertainOneTrust DataGuidance — A pending Senate Bill 220 would require private entities to obtain informed consent before collecting biometric data and to adopt written retention and destruction policies, with statutory damages of at least $5,000 per violation, but the bill has not been enacted.observed
ConfirmedNAAG — Attorneys general, including in Massachusetts, enforce privacy protections for sensitive categories of information such as health data primarily through federal statutes including HIPAA, alongside state consumer-protection and breach-notification law.observed
UncertainOneTrust DataGuidance — A pending House Bill 127 would define 'de-identified data' for K-12 student-data purposes only, limiting operators' ability to use such data outside narrowly permitted educational purposes; the bill has not been enacted.observed
Traffic-light rationale — RedNo comprehensive data-subject-rights framework; only narrow federal-sectoral rights apply.
Sub-modules (5)
Access RightAmber
Limited access rights exist only via federal sectoral law (FCRA credit-report access; HIPAA health-record access), not a general MA statute.
Claims (1):
The federal Fair Credit Reporting Act promotes accuracy and fairness in consumer-reporting-agency files and provides consumers limited rights to obtain and review their consumer reports, applicable to Massachusetts residents as part of the national FCRA regime.
Rectification And ErasureAmber
No general rectification/erasure right; FCRA affords limited dispute/correction rights for consumer-report inaccuracies.
Claims (1):
The FTC pursues an enforcement program against consumer-reporting agencies and furnishers under the FCRA that includes obligations related to inaccurate information, providing consumers an indirect correction pathway distinct from any general MA erasure right.
Restriction And ObjectionRed
No MA-specific restriction or objection-to-processing right identified.
Data PortabilityRed
No MA statutory data-portability right exists absent a comprehensive privacy law.
Claims (1):
Massachusetts confers no statutory right to data portability for consumer personal information, consistent with the absence of a comprehensive consumer-privacy law.
Deadlines And Response WindowsAmber
No general statutory response-deadline framework for data-subject rights requests; only breach-notification timing norms exist under Chapter 93H, without the precise statutory deadline language independently verified this session.
Claims (1):
Massachusetts' breach-notification statute governs timing of notice to the Attorney General and affected residents following a security breach, though the precise statutory deadline text was not independently retrieved and verified in this research session.
Category narrative65 words
Massachusetts confers no general access, rectification, erasure, restriction, objection, or portability rights on residents with respect to private-sector data holders. Limited, sector-specific access/correction rights exist under federal law (e.g., FCRA rights regarding consumer-report accuracy and disputes; HIPAA rights regarding health records held by covered entities). No MA-specific statutory response-deadline framework for consumer data-rights requests exists because no general rights regime exists to attach deadlines to.
Sources and claims (4)
ConfirmedFederal Trade Commission — The federal Fair Credit Reporting Act promotes accuracy and fairness in consumer-reporting-agency files and provides consumers limited rights to obtain and review their consumer reports, applicable to Massachusetts residents as part of the national FCRA regime.observed
ProbableFederal Trade Commission — The FTC pursues an enforcement program against consumer-reporting agencies and furnishers under the FCRA that includes obligations related to inaccurate information, providing consumers an indirect correction pathway distinct from any general MA erasure right.observed
ConfirmedNAAG — Massachusetts confers no statutory right to data portability for consumer personal information, consistent with the absence of a comprehensive consumer-privacy law.observed
UncertainIAPP — Massachusetts' breach-notification statute governs timing of notice to the Attorney General and affected residents following a security breach, though the precise statutory deadline text was not independently retrieved and verified in this research session.observed
Traffic-light rationale — AmberBinding security and breach-notification duties exist and are well-established, but broader accountability instruments (DPIA, DPO, ROPA) are absent.
Sub-modules (7)
Accountability And DpiaAmber
The WISP requirement under 201 CMR 17.00 functions as a risk-based accountability measure but is not a formal DPIA obligation.
Claims (1):
Massachusetts has several laws relating to data security and cybersecurity, and covered organisations that own or license personal information are subject to the obligations set forth under those applicable laws rather than a formal GDPR-style DPIA regime.
Dpo RequirementsRed
No statutory DPO-appointment requirement exists in Massachusetts.
Claims (1):
Massachusetts has no statutory requirement for covered entities to appoint a Data Protection Officer.
No Massachusetts-specific records-of-processing-activities obligation was identified outside of sector-level documentation duties such as those under HIPAA.
Joint Controller ArrangementsRed
No MA statutory joint-controller allocation framework exists; relationships are governed by ordinary contract law.
Security MeasuresGreen
Covered organisations owning or licensing MA residents' personal information must implement a written information security program with administrative, technical and physical safeguards under 201 CMR 17.00; MA law provides a compliance safe-harbour for entities already regulated by an equivalent federal security regime.
Claims (2):
Massachusetts data-security law provides that a person or agency complying with an applicable federal or state law offering equivalent or greater protection, such as GLBA or HIPAA safeguard regulations, is treated as satisfying the state's reasonable-security requirement, mirroring similar carve-outs in other states.
The FTC's Safeguards Rule requires financial institutions under FTC jurisdiction, including those operating in Massachusetts, to maintain an information security program with administrative, technical, and physical safeguards to protect customer information.
Breach NotificationGreen
Chapter 93H requires notice to the AG and affected residents following a breach of security, with distinctive restrictions on notice content compared to other states.
Claims (2):
Massachusetts General Law Chapter 93H requires notice to the Attorney General and to all potentially affected consumers in the event of a data breach, and the AG's office launched an online portal in 2018 to accept such notifications.
Unlike states such as California that mandate specific content and format for breach notices, Massachusetts law is distinctive in excluding certain background details about the breach from the required consumer notification.
Retention And DisposalAmber
Massachusetts imposes secure-disposal expectations tied to its data-security regulation, though a dedicated disposal-statute citation was not independently verified this session.
Claims (1):
Massachusetts data-security regulation obligates covered organisations that own or license personal information to address retention and secure disposal as part of their overall information-security obligations, though the precise disposal-statute citation was not independently confirmed via a retrievable primary source this session.
Category narrative71 words
This is the module with the strongest binding MA-specific content. 201 CMR 17.00 requires covered entities owning or licensing personal information of MA residents to maintain a written information security program (WISP) with administrative, technical, and physical safeguards; MA's data-breach-notification statute (Chapter 93H) imposes breach-notification duties; MA law provides carve-outs for entities already complying with federal security regimes such as GLBA/HIPAA. No GDPR-style DPIA, DPO-appointment, formal ROPA, or joint-controller framework exists.
Sources and claims (8)
ProbableOneTrust DataGuidance — Massachusetts has several laws relating to data security and cybersecurity, and covered organisations that own or license personal information are subject to the obligations set forth under those applicable laws rather than a formal GDPR-style DPIA regime.observed
ConfirmedNAAG — Massachusetts has no statutory requirement for covered entities to appoint a Data Protection Officer.observed
UncertainNAAG — No Massachusetts-specific records-of-processing-activities obligation was identified outside of sector-level documentation duties such as those under HIPAA.observed
ProbableIAPP — Massachusetts data-security law provides that a person or agency complying with an applicable federal or state law offering equivalent or greater protection, such as GLBA or HIPAA safeguard regulations, is treated as satisfying the state's reasonable-security requirement, mirroring similar carve-outs in other states.observed
ConfirmedFederal Trade Commission — The FTC's Safeguards Rule requires financial institutions under FTC jurisdiction, including those operating in Massachusetts, to maintain an information security program with administrative, technical, and physical safeguards to protect customer information.observed
ConfirmedOneTrust DataGuidance — Massachusetts General Law Chapter 93H requires notice to the Attorney General and to all potentially affected consumers in the event of a data breach, and the AG's office launched an online portal in 2018 to accept such notifications.observed
ConfirmedIAPP — Unlike states such as California that mandate specific content and format for breach notices, Massachusetts law is distinctive in excluding certain background details about the breach from the required consumer notification.observed
UncertainOneTrust DataGuidance — Massachusetts data-security regulation obligates covered organisations that own or license personal information to address retention and secure disposal as part of their overall information-security obligations, though the precise disposal-statute citation was not independently confirmed via a retrievable primary source this session.observed
Traffic-light rationale — AmberCross-border transfer coverage exists only via the federal DPF mechanism; no MA-specific transfer rules exist.
Sub-modules (6)
Transfer MechanismsAmber
No MA-specific transfer mechanism; entities rely on the federal EU-U.S. Data Privacy Framework where relevant.
Claims (1):
The European Commission issued an adequacy decision on the EU-U.S. Data Privacy Framework on July 17, 2023, providing a federal-level mechanism by which companies, including those operating in Massachusetts, may self-certify to transfer personal data from the EU to the United States.
Adequacy ReceivedAmber
Adequacy determinations regarding the US (e.g., EU adequacy for the DPF) are made at the federal level, not specific to Massachusetts.
Claims (1):
The European Commission issued an adequacy decision on the EU-U.S. Data Privacy Framework on July 17, 2023, providing a federal-level mechanism by which companies, including those operating in Massachusetts, may self-certify to transfer personal data from the EU to the United States.
Adequacy GrantedRed
Massachusetts, as a US state, does not independently grant adequacy determinations to other jurisdictions; this is a federal-level function.
Sccs And BcrsRed
No MA-specific SCC/BCR regime; any use is governed by counterparties' home-jurisdiction requirements (e.g., EU SCCs) rather than MA law.
Transfer Impact AssessmentRed
No MA or US-federal statutory TIA requirement was identified.
Data LocalisationRed
No Massachusetts data-localisation mandate was identified.
Category narrative43 words
Massachusetts has no state-specific cross-border transfer mechanism, adequacy regime, or data-localisation mandate. The operative adequacy mechanism for entities operating in Massachusetts is the federal EU-U.S. Data Privacy Framework, administered at the national level, which is a US-federal instrument rather than an MA-specific one.
Sources and claims (1)
ConfirmedFederal Trade Commission — The European Commission issued an adequacy decision on the EU-U.S. Data Privacy Framework on July 17, 2023, providing a federal-level mechanism by which companies, including those operating in Massachusetts, may self-certify to transfer personal data from the EU to the United States.observed
Traffic-light rationale — AmberStrong federal sectoral coverage; MA-specific sectoral overlays are thin or pending.
Sub-modules (7)
Financial Sector OverlayGreen
GLBA and the FTC Safeguards Rule govern financial institutions' handling of nonpublic personal information, applicable nationally including Massachusetts.
Claims (2):
The Gramm-Leach-Bliley Act requires financial institutions to explain their information-sharing practices to customers and to safeguard sensitive data, applicable to financial institutions operating in Massachusetts.
The FTC Safeguards Rule requires financial institutions under FTC jurisdiction to have measures in place to keep customer information secure, including institutions operating in Massachusetts.
Health Sector OverlayAmber
HIPAA governs protected health information at the federal level; no separate MA general health-privacy statute was confirmed beyond breach-notification law.
Claims (1):
Attorneys general, including in Massachusetts, work together and rely on HIPAA in addressing healthcare-related privacy violations affecting consumers' medical information.
Telecoms And EprivacyAmber
No Massachusetts-specific telecoms/ePrivacy statute was identified; the federal Telephone Consumer Protection Act and Telemarketing Sales Rule apply nationally.
Claims (1):
Federal telemarketing and consumer-protection law, including the Telephone Consumer Protection Act and the Telemarketing Sales Rule, has been the basis of significant multi-state enforcement actions applicable nationally, in the absence of an MA-specific ePrivacy statute.
Employment DataRed
No Massachusetts-specific employment-data-privacy statute was confirmed via retrievable sources this session.
Credit And ScoringGreen
The federal FCRA governs consumer-reporting and credit-scoring data nationally, including in Massachusetts.
Claims (1):
The Fair Credit Reporting Act promotes the accuracy, fairness, and privacy of information in consumer-reporting-agency files, and the FTC pursues an active enforcement program against CRAs, furnishers, and users of consumer reports nationally, including Massachusetts.
EducationAmber
A pending House Bill 127 would update Massachusetts' K-12 student-data-privacy statute to restrict vendor use, sale, and targeted advertising based on student data.
Claims (1):
Pending House Bill 127 would update Massachusetts' K-12 student-data statute by limiting how online service vendors may use, share, sell, or rent student data and by expanding definitions of covered and de-identified information.
InsuranceRed
No Massachusetts-specific insurance-data-security statute (e.g., an NAIC Insurance Data Security Model Law adoption) was confirmed this session; the NAIC's model privacy regulation for financial/health information exists as a template but MA-specific adoption was not independently verified.
Claims (1):
An NAIC model regulation governs privacy of consumer financial and health information for state-insurance-department licensees, including limits on disclosure of nonpublic personal financial information, but Massachusetts' specific adoption status of this or the NAIC Insurance Data Security Model Law was not independently confirmed this session.
Category narrative63 words
Federal sectoral statutes are the dominant source of enforceable duties touching Massachusetts data practices: GLBA/Safeguards Rule for financial institutions, HIPAA for health data, FCRA for credit/consumer-reporting, and COPPA for children (covered separately under children_and_vulnerable_groups). MA-specific overlays are limited to a pending K-12 student-data bill (HB 127) and general consumer-protection/breach law; no MA-specific insurance-data-security statute, telecoms/ePrivacy law, or employment-data statute was confirmed this session.
Sources and claims (7)
ConfirmedFederal Trade Commission — The Gramm-Leach-Bliley Act requires financial institutions to explain their information-sharing practices to customers and to safeguard sensitive data, applicable to financial institutions operating in Massachusetts.observed
ConfirmedFederal Trade Commission — The FTC Safeguards Rule requires financial institutions under FTC jurisdiction to have measures in place to keep customer information secure, including institutions operating in Massachusetts.observed
ConfirmedNAAG — Attorneys general, including in Massachusetts, work together and rely on HIPAA in addressing healthcare-related privacy violations affecting consumers' medical information.observed
ProbableNAAG — Federal telemarketing and consumer-protection law, including the Telephone Consumer Protection Act and the Telemarketing Sales Rule, has been the basis of significant multi-state enforcement actions applicable nationally, in the absence of an MA-specific ePrivacy statute.observed
ConfirmedFederal Trade Commission — The Fair Credit Reporting Act promotes the accuracy, fairness, and privacy of information in consumer-reporting-agency files, and the FTC pursues an active enforcement program against CRAs, furnishers, and users of consumer reports nationally, including Massachusetts.observed
UncertainOneTrust DataGuidance — Pending House Bill 127 would update Massachusetts' K-12 student-data statute by limiting how online service vendors may use, share, sell, or rent student data and by expanding definitions of covered and de-identified information.observed
UncertainNAIC (hosted via DataGuidance) — An NAIC model regulation governs privacy of consumer financial and health information for state-insurance-department licensees, including limits on disclosure of nonpublic personal financial information, but Massachusetts' specific adoption status of this or the NAIC Insurance Data Security Model Law was not independently confirmed this session.observed
Traffic-light rationale — RedNo comprehensive MA adtech/commercial-privacy statute; coverage is incidental via FTC Section 5 and a pending sector-specific bill.
Sub-modules (6)
Cookies And TrackersRed
No Massachusetts cookie/tracker consent statute was identified.
Dark PatternsAmber
Dark-pattern practices are addressed only via FTC Section 5 consent-order requirements defining affirmative express consent, not an MA-specific statute.
Claims (1):
FTC consent orders define 'Affirmative Express Consent' to exclude agreement obtained through user-interface designs manipulated so as to subvert or impair user autonomy, decision-making, or choice, operating as a federal dark-pattern check applicable to companies serving Massachusetts consumers.
Opt Out SignalsRed
No Massachusetts statutory recognition of universal opt-out signals (e.g., Global Privacy Control) was identified.
Clean Rooms And DcrRed
No Massachusetts clean-room/data-collaboration-room regulation was identified.
Cross Context AdvertisingAmber
No MA 'sale'/'share' definition exists; the only cross-context-advertising restriction identified is the pending HB 127 ban on targeted advertising using K-12 student data.
Claims (1):
Pending House Bill 127 would prohibit operators from engaging in targeted advertising based on information acquired through use of a K-12 site, service, or application, though it has not been enacted.
Direct MarketingAmber
No general MA direct-marketing consent statute was identified; federal telemarketing law (TCPA/TSR) applies nationally.
Claims (1):
Multi-state and federal enforcement, such as the action against Dish Network for violations of the Telemarketing Sales Rule and Telephone Consumer Protection Act, illustrates that direct-marketing suppression obligations in Massachusetts arise from federal telemarketing law rather than a dedicated MA direct-marketing statute.
Category narrative59 words
Massachusetts has no cookie-consent law, Global Privacy Control recognition statute, clean-room regulation, or CPRA-style 'sale'/'share' framework. The only MA-specific adtech-adjacent rule is the pending HB 127 prohibition on targeted advertising using K-12 student data. Dark-pattern and manipulative-design practices are addressed only through federal FTC Section 5 enforcement (e.g., consent-design requirements in FTC consent orders), not a dedicated MA statute.
Sources and claims (3)
ConfirmedFederal Trade Commission — FTC consent orders define 'Affirmative Express Consent' to exclude agreement obtained through user-interface designs manipulated so as to subvert or impair user autonomy, decision-making, or choice, operating as a federal dark-pattern check applicable to companies serving Massachusetts consumers.observed
UncertainOneTrust DataGuidance — Pending House Bill 127 would prohibit operators from engaging in targeted advertising based on information acquired through use of a K-12 site, service, or application, though it has not been enacted.observed
ProbableNAAG — Multi-state and federal enforcement, such as the action against Dish Network for violations of the Telemarketing Sales Rule and Telephone Consumer Protection Act, illustrates that direct-marketing suppression obligations in Massachusetts arise from federal telemarketing law rather than a dedicated MA direct-marketing statute.observed
A binding government-use facial-recognition restriction exists, but private-sector biometric, profiling, and ADM-transparency rules remain absent or pending.
Traffic-light rationale — AmberA binding government-use facial-recognition restriction exists, but private-sector biometric, profiling, and ADM-transparency rules remain absent or pending.
Sub-modules (6)
Profiling RestrictionsRed
No general MA profiling-restriction statute was identified for private-sector processing.
Automated Decision Making TransparencyRed
No MA-specific ADM-transparency or explanation-right statute was identified.
Ai Risk AssessmentsAmber
AI risk-assessment activity touching Massachusetts entities currently derives from federal FTC policy statements rather than a state AI statute.
Claims (1):
The FTC issued a proposed policy statement concerning the suppression of accuracy in artificial intelligence systems in mid-2026, representing federal-level AI-governance activity applicable to companies operating in Massachusetts in the absence of a state AI statute.
Biometric RegimeAmber
A private-sector biometric-data bill (SB 220) proposing consent and retention requirements remains pending; no enacted general biometric statute exists.
Claims (1):
Massachusetts Senate Bill 220 would expand definitions of biometric information and identifiers and require private entities holding biometric data to adopt written retention and destruction policies, but the bill remains pending and unenacted.
Genetic DataRed
No Massachusetts-specific genetic-data statute was confirmed via retrievable sources this session.
State Surveillance CarveoutsAmber
Massachusetts has banned some police/government use of facial recognition technology, representing a surveillance-limiting carve-out rather than a general surveillance exemption.
Claims (1):
Massachusetts has banned some police use of facial recognition technology, placing it alongside Virginia among states restricting government surveillance use of the technology.
Category narrative72 words
Massachusetts does not have a general profiling, ADM-transparency, or AI-risk-assessment statute. Its most concrete algorithmic/biometric governance step is a state-level restriction on government/law-enforcement use of facial recognition technology, enacted via 2020 police-reform legislation, distinguishing it from purely private-sector biometric statutes like Illinois' BIPA. A private-sector biometric-data bill (SB 220) remains pending and unenacted. AI risk-assessment activity affecting Massachusetts entities currently derives from federal FTC policy statements rather than an MA-specific AI law.
Sources and claims (3)
ProbableFederal Trade Commission — The FTC issued a proposed policy statement concerning the suppression of accuracy in artificial intelligence systems in mid-2026, representing federal-level AI-governance activity applicable to companies operating in Massachusetts in the absence of a state AI statute.observed
UncertainOneTrust DataGuidance — Massachusetts Senate Bill 220 would expand definitions of biometric information and identifiers and require private entities holding biometric data to adopt written retention and destruction policies, but the bill remains pending and unenacted.observed
ConfirmedIAPP — Massachusetts has banned some police use of facial recognition technology, placing it alongside Virginia among states restricting government surveillance use of the technology.observed
Traffic-light rationale — AmberStrong federal COPPA coverage; MA-specific K-12 protections remain pending; dependent-adults protections are an unaddressed gap.
Sub-modules (5)
Age VerificationAmber
The FTC issued an enforcement policy statement promoting adoption of age-verification technology in early 2026, applicable nationally including Massachusetts.
Claims (1):
The FTC issued an Enforcement Policy Statement Promoting the Adoption of Age-Verification Technology on February 25, 2026, a federal-level development applicable to services reaching Massachusetts minors.
Parental ConsentGreen
COPPA and its implementing Rule govern parental consent for children's data nationally, including for Massachusetts-based services and users.
Claims (1):
The FTC uses the COPPA Rule together with the FTC Act's prohibitions on deceptive and unfair practices to protect children's privacy, including parents' rights to control what data about their children is stored and deleted by covered services.
Minor Profiling BansAmber
Pending HB 127 would prohibit profiling students for advertising or other non-educational purposes using data gathered through K-12 educational technology.
Claims (1):
Pending House Bill 127 would prevent operators from using information gathered through K-12 educational technology to build a profile of a student, teacher, or administrator except for legitimate educational purposes, but the bill has not been enacted.
Education SettingsAmber
Pending HB 127 would update Massachusetts' K-12 student-data-privacy statute; it has not yet been enacted.
Claims (1):
House Bill 127 was discharged to the Massachusetts Joint Committee on Education in 2021 to update the state's K-12 student-data-privacy statute; its current enactment status was not independently confirmed as final this session.
Dependent AdultsRed
No Massachusetts-specific data-protection statute for dependent or elderly adults was confirmed via retrievable sources this session.
Category narrative64 words
Children's data protection touching Massachusetts is driven primarily by the federal COPPA framework and its FTC enforcement (including age-verification policy activity in 2026), plus a pending state-level K-12 student-data bill (HB 127) that would restrict vendor use of student data and ban targeted advertising to minors in educational settings. No MA-specific parental-consent statute beyond COPPA, and no dependent-adults-specific data-protection statute, was confirmed this session.
Sources and claims (4)
ProbableFederal Trade Commission — The FTC issued an Enforcement Policy Statement Promoting the Adoption of Age-Verification Technology on February 25, 2026, a federal-level development applicable to services reaching Massachusetts minors.observed
ConfirmedFederal Trade Commission — The FTC uses the COPPA Rule together with the FTC Act's prohibitions on deceptive and unfair practices to protect children's privacy, including parents' rights to control what data about their children is stored and deleted by covered services.observed
UncertainOneTrust DataGuidance — Pending House Bill 127 would prevent operators from using information gathered through K-12 educational technology to build a profile of a student, teacher, or administrator except for legitimate educational purposes, but the bill has not been enacted.observed
UncertainOneTrust DataGuidance — House Bill 127 was discharged to the Massachusetts Joint Committee on Education in 2021 to update the state's K-12 student-data-privacy statute; its current enactment status was not independently confirmed as final this session.observed
Active federal enforcement (FTC) and a dedicated state AG privacy division exist, but MA-specific 180-day developments are dominated by pending (not enacted) legislation.
Traffic-light rationale — AmberActive federal enforcement (FTC) and a dedicated state AG privacy division exist, but MA-specific 180-day developments are dominated by pending (not enacted) legislation.
Sub-modules (6)
Regulator Powers And PenaltiesAmber
The MA AG enforces Chapter 93A and Chapter 93H through its Data Privacy and Security Division; the FTC enforces Section 5 nationally.
Claims (2):
The Massachusetts Attorney General's Data Privacy and Security Division investigates and enforces the state's Consumer Protection Act and Data Breach Law.
The FTC charges defendants with violating Section 5 of the FTC Act, which bars unfair and deceptive acts and practices in or affecting commerce, as its principal enforcement tool for privacy and data-security matters nationally.
Enforcement Activity IndexAmber
2026 FTC enforcement activity includes location-data, dating-app data-sharing, student-data-security, and credit-reporting actions relevant to the broader US sectoral backdrop applicable in Massachusetts.
Claims (1):
In 2026 the FTC took multiple privacy/data-security enforcement actions of national applicability, including banning Kochava and a subsidiary from selling sensitive location data, an order against Illuminate over failure to secure students' personal data, action against Match and OkCupid for sharing personal data with third parties, and an FCRA action against RentGrow.
Regulator Funding And CapacityGreen
The MA AG's creation of a standalone Data Privacy and Security Division signals investment in dedicated privacy-enforcement capacity.
Claims (1):
In creating a standalone Data Privacy and Security Division, the Massachusetts AG's office joined a minority of states, primarily larger ones, with a dedicated privacy-enforcement unit.
Collective Redress And Class ActionsAmber
Chapter 93A Sections 2, 4, and 9 are cited together in federal enforcement literature, consistent with a structure combining AG enforcement (Section 4) and a separate consumer enforcement provision (Section 9), though the data-privacy-specific scope of Section 9 as a private/class remedy was not independently verified this session.
Claims (1):
Federal enforcement-comparison literature cites Massachusetts General Laws Chapter 93A Sections 2, 4, and 9 together as the state's consumer-protection framework, consistent with a structure in which Section 4 empowers Attorney General enforcement and Section 9 provides a separate provision commonly associated with consumer civil actions, though this session could not independently confirm Section 9's precise scope for data-privacy claims via primary text.
Private Right Of ActionAmber
See collective_redress_and_class_actions; a distinct data-privacy-specific private right of action beyond Chapter 93A's general consumer-protection remedy was not confirmed this session.
Claims (1):
Federal enforcement-comparison literature cites Massachusetts General Laws Chapter 93A Sections 2, 4, and 9 together as the state's consumer-protection framework, consistent with a structure in which Section 4 empowers Attorney General enforcement and Section 9 provides a separate provision commonly associated with consumer civil actions, though this session could not independently confirm Section 9's precise scope for data-privacy claims via primary text.
Recent Developments 180DAmber
Within the 180 days preceding the run date, the principal Massachusetts-relevant developments were (a) continued legislative activity on comprehensive privacy bills without final enactment, and (b) a steady cadence of federal FTC enforcement actions and policy statements (AI accuracy suppression policy, age-verification enforcement policy, Illuminate student-data order, Kochava location-data order) that apply nationally including in Massachusetts.
Claims (1):
Within the 180 days preceding the run date, the Massachusetts House passed a Consumer Data Privacy bill and the Senate had separately passed its own Consumer Data Privacy Act version, without confirmed reconciliation or gubernatorial signature, while federal FTC activity (AI accuracy-suppression policy statement, age-verification enforcement policy, Illuminate and Kochava orders) continued to apply nationally.
Category narrative101 words
Enforcement touching Massachusetts data practices is bifurcated: the state AG enforces the Consumer Protection Act (Chapter 93A) and the Data Breach Law (Chapter 93H) through a dedicated Data Privacy and Security Division, while the FTC brings frequent Section 5, COPPA, FCRA, and Safeguards Rule actions nationally, several in 2026 (Kochava location-data ban, Match/OkCupid data-sharing case, Illuminate student-data-security order, RentGrow FCRA action). Chapter 93A Section 9 is cited alongside Section 2 and Section 4 in federal enforcement literature, consistent with a private civil-enforcement mechanism operating alongside AG authority, though the data-privacy-specific scope of that private right was not independently verified this session.
Sources and claims (6)
ProbableIAPP — The Massachusetts Attorney General's Data Privacy and Security Division investigates and enforces the state's Consumer Protection Act and Data Breach Law.observed
ConfirmedFederal Trade Commission — The FTC charges defendants with violating Section 5 of the FTC Act, which bars unfair and deceptive acts and practices in or affecting commerce, as its principal enforcement tool for privacy and data-security matters nationally.observed
ConfirmedFederal Trade Commission — In 2026 the FTC took multiple privacy/data-security enforcement actions of national applicability, including banning Kochava and a subsidiary from selling sensitive location data, an order against Illuminate over failure to secure students' personal data, action against Match and OkCupid for sharing personal data with third parties, and an FCRA action against RentGrow.observed
ProbableIAPP — In creating a standalone Data Privacy and Security Division, the Massachusetts AG's office joined a minority of states, primarily larger ones, with a dedicated privacy-enforcement unit.observed
UncertainFederal Trade Commission — Federal enforcement-comparison literature cites Massachusetts General Laws Chapter 93A Sections 2, 4, and 9 together as the state's consumer-protection framework, consistent with a structure in which Section 4 empowers Attorney General enforcement and Section 9 provides a separate provision commonly associated with consumer civil actions, though this session could not independently confirm Section 9's precise scope for data-privacy claims via primary text.observed
UncertainOneTrust DataGuidance — Within the 180 days preceding the run date, the Massachusetts House passed a Consumer Data Privacy bill and the Senate had separately passed its own Consumer Data Privacy Act version, without confirmed reconciliation or gubernatorial signature, while federal FTC activity (AI accuracy-suppression policy statement, age-verification enforcement policy, Illuminate and Kochava orders) continued to apply nationally.observed
No categories match.
Filters combine as OR inside a group and AND across
groups.
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for United States – Massachusetts
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
not recorded
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-06. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 48 claim(s), 27 source(s) in the cumulative register.
GDPR article map
Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).
All 10 modules were populated with narrative, traffic-light, and claims. Strong T1 (FTC primary pages) and T2 (NAAG, NAIC) coverage exists for the federal sectoral backdrop (FTC Act Section 5, GLBA/Safeguards Rule, FCRA, COPPA) and for Massachusetts' binding breach-notification/data-security instruments (Chapter 93H, 201 CMR 17.00 via secondary confirmation). Coverage of pending Massachusetts comprehensive-privacy, biometric (SB 220), and student-data (HB 127) legislation relied on T3/T4 secondary sources (IAPP, DataGuidance) because primary Massachusetts legislative-tracking pages were outside this session's retrieval allowlist and DataGuidance's substantive notes were paywalled beyond headlines. Modules with genuine regulatory gaps (data_subject_rights, cross_border_and_adequacy sub-modules on adequacy-granted/SCCs/TIA/localisation, several children_and_vulnerable_groups and adtech sub-modules) are marked red/amber with explicit absent_field_provenance rather than fabricated obligations, consistent with the seed's CRITICAL disambiguation that Massachusetts lacks a comprehensive consumer-privacy statute.
Unresolved questions (6):
Has the Massachusetts House bill (passed ~June 2026) and Senate bill (passed ~September 2025) on comprehensive consumer data privacy been reconciled in conference committee, and has either version been signed by the Governor?
What is the current, exact statutory notification-timing language of M.G.L. c. 93H (e.g., 'as soon as practicable and without unreasonable delay') per primary mass.gov text?
Does Massachusetts General Laws Chapter 93A Section 9 provide a private right of action / class-action remedy specifically applicable to data-privacy and data-security violations, and what are its damages/scope limits?
Has Massachusetts adopted the NAIC Insurance Data Security Model Law or an equivalent insurance-sector data-security statute?
What is the exact citation and current text of the Massachusetts records-disposal statute (commonly referenced elsewhere as M.G.L. c. 93I), which could not be independently verified via a retrievable primary source this session?
Has the pending K-12 student-data bill (HB 127) or the biometric-data bill (SB 220) progressed beyond committee referral since their last confirmed 2021 status?