Massachusetts Data Security Regulation (201 CMR 17.00)

· About Massachusetts Data Security Regulation (201 CMR 17.00)

Key Takeaways

  • 201 CMR 17.00 applies to any person that owns or licenses personal information about a Massachusetts resident, including out-of-state companies, and it has required full compliance since 1 March 2010.[1][2]
  • The regulation is enforced through Massachusetts consumer-protection authority under M.G.L. c. 93H, and the official text remains in force with no 2025–2026 amendment or delayed effective date reflected in the current published regulation.[1][2]
  • Covered organizations must maintain a written information security program, designate one or more responsible employees, and train staff with access to personal information.[1][6]
  • The regulation requires encryption of personal information transmitted over public networks and stored on portable devices when reasonably feasible, plus technical and physical safeguards appropriate to the organization’s size, scope, and resources.[1][14]
  • A separate statutory breach-notice regime under M.G.L. c. 93H can trigger notification duties and enforcement where unsecured personal information of Massachusetts residents is compromised.[2]
  • Civil penalties under the Massachusetts data-breach statute can reach up to $5,000 per violation, and enforcement can also include injunctive relief and other consumer-protection remedies.[2]

What It Is

201 CMR 17.00 is Massachusetts’ data-security regulation for the protection of personal information of residents of the Commonwealth.[1][2] It implements M.G.L. c. 93H and sets minimum administrative, technical, and physical safeguards for paper and electronic records containing covered personal information.[1][2]

The regulation is issued under Massachusetts consumer-protection authority and is administered in the state’s regulatory framework for standards protecting resident personal information.[1][7] The current official regulation states that persons who own or license such information must be in full compliance on or before 1 March 2010.[2][6]

The published official text available in 2026 shows no new adoption date, no later phase-in date, and no 2025–2026 delayed effective date for the rule itself.[1][2] The regulation remains active and is still described by the Commonwealth as establishing minimum safeguards for personal information.[1]

Who Must Comply

The rule applies to all persons that own or license personal information about a resident of the Commonwealth, not just businesses physically located in Massachusetts.[1][2] The FAQs state that the regulation reaches those engaged in commerce and who collect and retain personal information in connection with providing goods or services or for employment purposes.[14]

The regulation’s applicability is not limited by headquarters location, so an out-of-state controller or vendor can be covered if it owns or licenses Massachusetts residents’ personal information.[1][14] The FAQs also explain that the rule does not apply to natural persons who are not in commerce.[14]

The FAQ materials further state that Massachusetts public entities are excluded from the definition of “person,” so state agencies and political subdivisions are not covered by 201 CMR 17.00.[14] The rule is therefore aimed primarily at private-sector data holders and their service providers.

The regulation itself does not create a turnover- or employee-count threshold; coverage turns on possession of Massachusetts residents’ personal information.[1][2] In practical terms, if an organization holds covered personal information, it should assume the rule applies unless a clear exclusion applies.[1][14]

Core Requirements

  1. Maintain a written information security program. Covered organizations must develop, implement, and maintain a comprehensive, written WISP that addresses the security of personal information across the organization.[1][6]
  2. Assign responsibility. The program must designate one or more employees to maintain it, and those employees must receive periodic training on the program and the handling of personal information.[1][6]
  3. Limit access to personal information. Access must be restricted to those persons who need it to perform their jobs, using role-based controls and other least-privilege measures.[1][6]
  4. Conduct risk-based security assessments. Organizations must identify and assess foreseeable internal and external risks to the security, confidentiality, and integrity of personal information and evaluate the sufficiency of existing safeguards.[1][6]
  5. Encrypt sensitive transmissions and portable storage. The regulation requires encryption of personal information transmitted over public networks and stored on laptops, flash drives, or other portable devices when reasonable and technically feasible.[14]
  6. Dispose of records securely. Organizations must take reasonable steps to destroy or erase personal information no longer to be retained so that it cannot practicably be read or reconstructed.[1][6]
  7. Vet third-party service providers. Organizations must take reasonable steps to select and retain service providers capable of maintaining appropriate safeguards and require those providers by contract to protect personal information.[1][6]
  8. Maintain physical and technical protections. The program must include protections such as secure user authentication, audit controls, and facility safeguards proportionate to the data and environment.[1][6]

Deadlines and Penalties

| milestone | date | what applies | |---|---:|---| | regulation compliance deadline | 1 March 2010 | Full compliance with 201 CMR 17.00 required.[2] | | current official text in effect | 6 September 2026 | Regulation remains active; no published 2025–2026 delay or sunset appears in the official text.[1][2] | | breach-notice trigger | upon discovery of breach | Separate M.G.L. c. 93H notice duties may apply if Massachusetts residents’ personal information is compromised.[2] |

Massachusetts’ data-security framework is backed by enforcement under the Commonwealth’s consumer-protection and data-breach laws.[2] The statute provides for civil penalties of up to $5,000 per violation for breaches of the personal-information law, and enforcement can also seek injunctions and other relief depending on the facts.[2]

The practical sanction risk under 201 CMR 17.00 is not just fines; it also includes state investigation, mandated remediation, and exposure in any related breach litigation or attorney general action.[2] Organizations should treat written-program failures and encryption failures as compliance defects, not merely technical issues.[1][2]

How to Comply

  1. Inventory covered data. Identify where Massachusetts residents’ personal information is collected, stored, transmitted, archived, and deleted, including backups and vendor systems.[1][2]
  2. Build or update the WISP. Map the required controls into a written security program, then assign a responsible owner and formal review cycle.[1][6]
  3. Use ISO 27001 as the control backbone. ISO 27001 maps well to governance, risk treatment, access control, supplier management, incident management, and continuous improvement.[1][6]
  4. Align operational controls to NIST CSF 2.0. Use NIST CSF 2.0 to structure identify, protect, detect, respond, and recover activities, especially for asset management, access control, logging, and incident response.
  5. Adopt ISO 42001 where AI systems process personal information. If AI systems ingest or infer Massachusetts residents’ personal information, use ISO 42001 to govern model risk, accountability, data lifecycle controls, and human oversight.
  6. Encrypt and harden endpoints. Apply strong encryption to covered transmissions and portable devices, plus MFA, device management, patching, and secure configuration.[14]
  7. Contractually bind vendors. Update data-processing and service-provider agreements to require equivalent safeguards, breach cooperation, and return or destruction of personal information at termination.[1][6]
  8. Test and evidence compliance. Run periodic risk assessments, tabletop exercises, access reviews, and internal audits, and retain evidence showing the program was implemented and maintained.[1][6]

Related Regulations

  • M.G.L. c. 93H is the enabling Massachusetts statute for breach notification and enforcement, and 201 CMR 17.00 operationalizes its security standard.[2]
  • M.G.L. c. 93A can overlap when weak security practices are framed as unfair or deceptive conduct in consumer or business litigation.[2]
  • GLBA Safeguards Rule may overlap for financial institutions, but Massachusetts can still impose its own security obligations for Massachusetts residents’ data.[1][2]
  • HIPAA Security Rule may apply to health data and can coexist with 201 CMR 17.00 if the organization is handling Massachusetts residents’ personal information outside a HIPAA-covered context.
  • Massachusetts Data Privacy Act proposals in 2025–2026 appear separate from 201 CMR 17.00 and do not replace this regulation; they may create additional duties if enacted.[12][13]

FAQ

Does 201 CMR 17.00 apply to companies outside Massachusetts?

Yes. The rule applies to anyone that owns or licenses personal information about a Massachusetts resident, regardless of the company’s physical location.[1][14] A vendor, SaaS provider, or employer outside Massachusetts can be covered if it holds that data. The key question is data ownership or licensing, not corporate domicile.[1][14]

Does the rule apply to personal data kept only on paper?

Yes. The regulation expressly covers personal information in both paper and electronic records.[1][2] Organizations must therefore secure physical files, retention areas, shredding processes, and locked-storage practices in addition to cybersecurity controls.[1][6]

Does 201 CMR 17.00 require encryption?

Yes, but the rule is framed as reasonable and technically feasible for certain contexts rather than a blanket one-size-fits-all technology mandate.[14] The FAQ materials specifically mention encryption of personal information on portable devices and over public networks.[14] Organizations should document any claim that encryption is not technically feasible.[14]

Are Massachusetts public agencies subject to 201 CMR 17.00?

No, the FAQ materials state that the definition of “person” excludes agencies, executive offices, departments, boards, commissions, bureaus, divisions, authorities, and political subdivisions of the Commonwealth.[14] That means state agencies and municipalities are not covered by this particular regulation.[14]

What is the main penalty risk for noncompliance?

The biggest immediate risk is state enforcement tied to poor safeguards or a reportable breach, not a standalone administrative fine schedule in the regulation text itself.[1][2] Under the related Massachusetts breach law, civil penalties can reach up to $5,000 per violation, and the attorney general can also pursue injunctive and remedial relief.[2]

Sources

Put it into practice

More compliance guides