HD 707 defines new categories of sensitive personal information requiring protection, including biometric data (like fingerprints), genetic information, health insurance details, medical history, and precise geolocation data. It updates the definition of "breach of security" to cover unauthorized access to unencrypted data or encrypted data where keys were compromised, with exceptions for legitimate employee actions. The bill requires organizations experiencing a breach to notify both the Attorney General and Consumer Affairs agency, detailing the compromised data types (e.g., biometric or medical information), and to certify credit monitoring services meet new standards - though medical or geolocation data breaches may exempt the notification requirement. This directly affects businesses, government agencies, and healthcare providers handling residents' personal data in Massachusetts.
HD 1083 prohibits "negative option" sales where consumers are automatically charged after a trial period unless they actively cancel. It requires sellers to clearly explain all costs, cancellation methods, and deadlines before a trial offer, and to obtain explicit consumer agreement before charging. The bill also bans financial institutions from sharing customers' personal or financial data without their specific permission, with limited exceptions like direct customer authorization. This directly affects consumers by preventing surprise charges and unauthorized data sharing, and impacts businesses (sellers and financial institutions) by mandating clear disclosures and consent.
This bill requires state agencies to share constituent personal information directly with legislators or their staff when assisting a person with state services. It removes the need for agencies to get authorization from the constituent (unless federal law requires it) for this disclosure. The law directly affects constituents seeking help, legislators, and agency staff handling such requests. Key provision: Agencies must provide necessary information to help legislators address constituent needs without requiring additional consent. This streamlines assistance but maintains existing federal privacy requirements.
SD 1491 protects transportation network driver data privacy by making records held by the state Board confidential and non-public under Chapter 150F. It requires transportation network companies and driver organizations to follow strict data security protocols, including encryption, access controls, and breach protocols, while prohibiting disclosure of driver information for immigration enforcement without a court order. The bill directly affects ride-hailing companies (like Uber/Lyft), driver organizations, and the state Board, mandating specific regulations by 2025-2026 to govern data handling, consent, and sharing during bargaining. Key provisions include limiting data collection to necessary information, requiring driver consent for data sharing, and establishing procedures for verifying driver eligibility and bargaining representation. The law aims to balance bargaining transparency with robust privacy safeguards for drivers.
This bill creates a civil cause of action for individuals whose personal information (such as home address, phone number, or email) is maliciously shared without consent, with intent to cause harassment, stalking, injury, or death. To win a lawsuit, a plaintiff must prove the defendant knowingly disseminated their information without consent, with malicious intent, and that the sharing posed an immediate threat or caused actual harm. If successful, plaintiffs can recover damages, attorney fees, and other remedies, with courts considering if sensitive details (like health care or identity information) were shared alongside the personal data. The bill excludes liability for internet service providers, reporting of suspected crime, protected speech, or petitioning activities, and requires lawsuits to be filed within two years of the incident.
This bill strengthens data privacy for Massachusetts state systems by clarifying which activities qualify as "criminal justice duties" and restricting data sharing. It prohibits state agencies from sharing motor vehicle records with federal agencies for civil immigration enforcement, except when a valid warrant is presented. The bill also blocks access to criminal offender records for non-criminal justice purposes, like civil enforcement, and requires federal agencies to certify their use of such data solely for criminal justice. These provisions directly affect state agencies managing data (like the motor vehicle registry) and federal entities seeking access to state databases.
By Representative Owens of Watertown, a petition (accompanied by bill, House, No. 1926) of Steven Owens and Lindsay N. Sabadosa relative to tenant data privacy. The Judiciary.
HD 5363 requires major social media platforms operating in Massachusetts to conduct monthly algorithm audits focused on child safety risks, such as mental health harms, addictive behaviors, and exposure to harmful content like tobacco or gambling. Covered platforms - defined as those processing personal data for 100,000+ Massachusetts residents or meeting specific revenue thresholds - must register annually with the Attorney General’s office, pay for independent audits, and submit transparency reports starting in 2026. The law mandates audits to assess whether platforms are "likely to be accessed" by children (e.g., through audience composition or marketing) and to evaluate algorithmic risks like bullying or predatory marketing. It establishes an Office of Social Media Transparency and Accountability within the Attorney General’s office to enforce these requirements and oversee an expert Advisory Council.
This bill (HD 4038) defines "protected information" as data about individuals' political, religious, or social views, associations, or activities, and restricts Massachusetts law enforcement from collecting or sharing this data without specific justification. It requires criminal intelligence systems (like fusion centers) to conduct annual audits tracking data access, maintain detailed logs of protected information sharing, and destroy unreliable data every five years. Law enforcement must obtain written authorization to investigate based on protected information and can only share such data with other agencies after prior written approval. The bill directly affects Massachusetts residents by limiting how state agencies handle sensitive personal information related to beliefs and associations.
By Mr. Finegold, a petition (accompanied by bill, Senate, No. 39) of Barry R. Finegold for legislation to protect sensitive personal information from breaches and other cybersecurity incidents by creating a Massachusetts Cyber Incident Response Team. Advanced Information Technology, the Internet and Cybersecurity.