Massachusetts Data Privacy Law
· About Massachusetts Data Privacy Law
Key Takeaways
- The Massachusetts consumer privacy framework is not yet enacted statewide law as of 6 September 2026; the House and Senate have each passed different versions, and the bills remain in reconciliation/conference. [1][4][15]
- The operative proposal would apply to entities that control or process personal data of at least 100,000 consumers, with a lower threshold for entities deriving revenue from data sales, and it would reach conduct affecting Massachusetts residents and persons present in the Commonwealth. [3][4]
- The proposal grants rights to access, correct, delete, port, and opt out of targeted advertising and certain sales or profiling, and it restricts processing of sensitive data without affirmative consent. [1][4]
- The House version would make sale of precise geolocation data prohibited and would add special protections for minors and sensitive data. [1][3]
- Enforcement in the current bills is centered on the Massachusetts Attorney General, with bill text and summaries indicating a cure period in the early years and civil penalties treated as unfair or deceptive trade practices. [12][13]
- Because the law is still pending, compliance teams should build to the proposal now but track final enacted text for any changes to thresholds, effective dates, cure rights, or private litigation exposure. [4][15]
What It Is
Massachusetts does not currently have a final, enacted “Massachusetts Data Privacy Law” comparable to California’s CPRA or Virginia’s VCDPA. Instead, the Commonwealth has advanced comprehensive privacy legislation through both chambers: the Senate passed the Massachusetts Data Privacy Act on 25 September 2025, and the House passed the Massachusetts Consumer Data Privacy Act on 4 June 2026. [1][4] The Senate bill is S.2608 and the House substitute is H.5472; both are tracked on the Massachusetts Legislature site, and the House text states an effective date of 1 July 2027 for Section 1. [2][6]
The legislation is designed to regulate the collection, use, sharing, and sale of personal data of Massachusetts residents, and it assigns enforcement primarily to the Massachusetts Attorney General under the state’s consumer protection framework. [1][4][12] The current public materials indicate a conference committee process to reconcile the House and Senate versions, so any summary of “the law” must be treated as a summary of pending legislation, not enacted code, until final passage and gubernatorial action occur. [15]
Key dates currently visible in official bill text are as follows: the Senate bill text reflected 1 January 2027 and 1 June 2027 effective dates in the 2025 filed version, while the House substitute published in 2026 provides for 1 July 2027 for the main operative section. [6][9][11] No final enacted date could be confirmed from the available official materials as of 6 September 2026. [2][6][15]
Who Must Comply
The proposal applies to persons and entities that conduct business in Massachusetts or produce products or services targeted to Massachusetts residents and that meet the applicable processing thresholds. [1][3][4] Public reporting on the House bill states a threshold of 100,000 consumers for companies that control or process personal data, and the Senate and House materials also describe the law as covering companies handling the data of Massachusetts residents. [3][4][12]
The bills also include a lower threshold for data brokers or revenue from data sales in some versions of the proposal, although the precise language should be checked against the final enrolled text because the threshold structure has shifted between drafts. [1][12][13] The House summary expressly notes that the bill grants rights to “residents of and those present in Massachusetts,” indicating an extraterritorial effect based on consumer location and state nexus rather than incorporation in the Commonwealth alone. [1]
Exemptions and carveouts are also part of the proposal. Public summaries note a loyalty program carveout in the House version, and the bill drafts preserve certain entity-level exemptions and activity-specific exemptions that should be reviewed before relying on general applicability claims. [3][15] As with other state privacy laws, organizations already regulated under sectoral regimes should not assume full exemption unless the final Massachusetts text expressly says so. [1][4]
Core Requirements
- Consumer rights program: Controllers must provide mechanisms for consumers to access, correct, delete, and obtain a portable copy of personal data, and to opt out of targeted advertising, certain sales, and certain profiling uses. [1][4]
- Data minimization and purpose limitation: Collection must be limited to what is reasonably necessary and proportionate to the disclosed purposes, with deletion or de-identification when data is no longer needed for those purposes. [4][5]
- Sensitive data controls: Sensitive data, including categories such as biometric, genetic, health, precise geolocation, and data revealing protected characteristics, cannot be processed or sold without affirmative consent or another clearly stated lawful basis in the final text. [1][3][4]
- Children and teen protections: The House materials describe strong protections for minors, including tighter limits on sale or sharing and enhanced consent expectations, so youth-directed products need age-aware design and consent logic. [1][3]
- Sale and targeted advertising limits: The proposal gives consumers the right to opt out of targeted advertising and data sales, and the House version would impose a blanket ban on the sale of precise geolocation data. [1][4]
- Security safeguards: Businesses must implement reasonable technical and organizational safeguards to protect personal data, aligning privacy compliance with established information security controls. [1][10]
- Controller governance and notices: Companies must provide transparent privacy notices describing categories collected, purposes, third parties, and consumer rights, and must operationalize internal intake, authentication, and response workflows. [4][5]
Deadlines and Penalties
| milestone | date | what applies | |---|---:|---| | Senate passage | 25 September 2025 | Senate approved S.2608, but it was not final law. [4][9] | | House passage | 4 June 2026 | House passed H.5472 / the Consumer Data Privacy Act substitute. [1][6] | | Main effective date in House text | 1 July 2027 | Section 1 of the House bill takes effect. [6] | | Earlier effective dates in Senate text | 1 January 2027 / 1 June 2027 | Earlier version of the Senate bill used phased dates for different sections. [9] |
Maximum penalties and sanctions in the publicly available materials are still tied to the final enacted version, which has not been confirmed as of 6 September 2026. The bill materials and summaries indicate that violations would be enforced by the Attorney General under Massachusetts consumer protection authority and treated as unfair trade practices, exposing businesses to civil penalties and injunctive relief. [12][13] Public summaries also indicate a cure period in early years of enforcement in some drafts, but because the reconciliation process is ongoing, the final cure structure and any private right of action must be verified against the enacted text. [12][15]
How to Comply
- Map data and decide applicability: Identify whether the business hits the Massachusetts threshold, including resident counts, targeted services, and any revenue-from-data-sales metric in the final text. Use a single data inventory as the foundation for all state privacy obligations. [1][3][4]
- Classify data and use cases: Tag personal data, sensitive data, children’s data, precise geolocation, targeted advertising, sale, and profiling use cases so each processing purpose has a lawful basis and a control owner. [1][4]
- Build rights operations: Create intake, verification, response, appeal, and deletion workflows that can service access, correction, portability, deletion, and opt-out requests within statutory timelines. [1][4]
- Implement consent and preference systems: Separate affirmative consent for sensitive data from general privacy choices, and ensure opt-out signals flow into ad-tech, data sharing, and downstream vendor systems. [1][3][4]
- Harden security controls: Align the privacy program with ISO 27001 for an ISMS, use NIST CSF 2.0 to structure govern-identify-protect-detect-respond-recover activities, and use ISO 42001 where automated decision-making or AI systems affect consumer data. [10]
- Contract and vendor manage: Update processor and service-provider agreements to prohibit unauthorized use, require assistance with consumer rights, define subprocessors, and impose audit and security obligations. [4][5]
- Document governance and training: Maintain records of processing activities, DPIA-style risk reviews for sensitive and high-risk processing, and training for product, marketing, legal, and support teams. [4][10]
- Track the final bill text: Re-check the final enrolled version for effective dates, cure rights, private litigation, and any changes to exemptions or thresholds before launch or scaling. [15]
Related Regulations
- California Consumer Privacy Act / CPRA: California is the most mature U.S. state privacy regime; Massachusetts proposals borrow familiar rights such as access, deletion, correction, and opt-out, but may differ on age protections and geolocation sales.
- Virginia Consumer Data Protection Act: Virginia is a useful comparator for controller/processor governance, consumer rights, and sensitive data consent, though Massachusetts proposals appear more restrictive on certain data types.
- Colorado Privacy Act: Colorado is relevant because its risk assessment and universal opt-out concepts mirror themes appearing in Massachusetts drafts, especially around targeted advertising and sensitive data.
- Connecticut Data Privacy Act: Connecticut overlaps on rights, notice, and processing limits, but Massachusetts bills may create different thresholds and enforcement design.
- Massachusetts consumer protection law, Chapter 93A: The draft privacy bills appear to leverage unfair trade practice enforcement, so Chapter 93A concepts remain central to penalty and injunction analysis. [12][13]
FAQ
Does the Massachusetts data privacy law already apply to companies outside Massachusetts?
Not yet as a final enacted statute. As of 6 September 2026, the Commonwealth has passed bills in each chamber, but reconciliation is still underway, so no final statewide privacy law can be cited as fully effective. [4][15]
Does the proposal cover small businesses?
The current public materials indicate it is aimed at larger data processors, with a threshold of 100,000 consumers in the House summary and additional threshold logic in some drafts for revenue tied to data sales. Smaller businesses below the thresholds may be out of scope, but final text controls and exemptions should be checked carefully. [3][12][13]
Are sensitive data and precise location data treated differently?
Yes. The proposal treats sensitive data as requiring stronger controls, including affirmative consent in the House and Senate materials, and the House version highlights a ban on selling precise geolocation data. [1][3][4]
What rights do consumers get under the bill?
Consumers would get access, correction, deletion, portability, and opt-out rights for targeted advertising and certain sales or profiling uses. The proposal also requires transparent notice and mechanisms to submit and appeal requests. [1][4]
What penalties can companies face?
The bill materials indicate enforcement by the Massachusetts Attorney General, with violations treated as unfair or deceptive practices and exposure to civil penalties and injunctive relief. The final penalty amounts and any private right of action remain contingent on the final enacted text. [12][13][15]
Should companies start complying before enactment?
Yes. The safest approach is to build the program now because the core obligations in the House and Senate versions are already stable enough to support implementation, even though the final dates and some enforcement details could still change. [1][4][15]
Sources
- Massachusetts Legislature — Press Release: Massachusetts Consumer Data Privacy Act
- Massachusetts Legislature — Press Release: Senate Passes the Massachusetts Data Privacy Act
- Massachusetts Legislature — Bill S.2619
- Massachusetts Legislature — Bill S.2608 PDF
- Massachusetts Legislature — Bill H.5472 PDF
- Massachusetts Legislature — Bill H.4746
- WBUR — Mass. House unanimously passes data privacy bill
- DataGuidance — Massachusetts: House passes Consumer Data Privacy bill
- Massachusetts law about privacy — Mass.gov
- ACLU Massachusetts — Data Privacy Now!
Put it into practice
- Generate the policy: Privacy policy generator (generatepolicy.com)
- Buy the policy pack: State Privacy Law Checklist (cyberpolicy.shop)
- Build it yourself: 2026 US Privacy Program Workbook (ciso.diy)