Cookies help us display personalized product recommendations and ensure you have great shopping experience.

By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
SmartData CollectiveSmartData Collective
  • Analytics
    AnalyticsShow More
    predictive analytics risk management
    How Predictive Analytics Is Redefining Risk Management Across Industries
    7 Min Read
    data analytics and gold trading
    Data Analytics and the New Era of Gold Trading
    9 Min Read
    composable analytics
    How Composable Analytics Unlocks Modular Agility for Data Teams
    9 Min Read
    data mining to find the right poly bag makers
    Using Data Analytics to Choose the Best Poly Mailer Bags
    12 Min Read
    data analytics for pharmacy trends
    How Data Analytics Is Tracking Trends in the Pharmacy Industry
    5 Min Read
  • Big Data
  • BI
  • Exclusive
  • IT
  • Marketing
  • Software
Search
© 2008-25 SmartData Collective. All Rights Reserved.
Reading: Massachusetts’ New ID Theft Protection Regulations- Extended Deadline
Share
Notification
Font ResizerAa
SmartData CollectiveSmartData Collective
Font ResizerAa
Search
  • About
  • Help
  • Privacy
Follow US
© 2008-23 SmartData Collective. All Rights Reserved.
SmartData Collective > Business Intelligence > Massachusetts’ New ID Theft Protection Regulations- Extended Deadline
Business Intelligence

Massachusetts’ New ID Theft Protection Regulations- Extended Deadline

CariBirkner
CariBirkner
4 Min Read
SHARE

In light of emerging economic uncertainties for companies, Massachusets has extended the deadline for compliance with its new consumer privacy guidelines. 201 CMR 17.00 was originally set to go into effect January 1, 2009, but has been extended until May 1, 2009 to allow companies more time to get their consumer data protection plans in order.

The Massachusets Office of Consumer Affairs and Business Regulation has published a lengthy checklist fo…

In light of emerging economic uncertainties for companies, Massachusets has extended the deadline for compliance with its new consumer privacy guidelines. 201 CMR 17.00 was originally set to go into effect January 1, 2009, but has been extended until May 1, 2009 to allow companies more time to get their consumer data protection plans in order.

More Read

AI VR and BIG Data
3 Ways AI and VR Combine with Big Data to Enhance Business
Great BI, or Getting By? [Webinar] – Today at 2pm ET
4 Tips to Simplify Your Business Rules
Starting Your Business: Data From the Ground Up
Operational decision making as a corporate asset

The Massachusets Office of Consumer Affairs and Business Regulation has published a lengthy checklist for compliance which is available at  their website. The main requirement of the new regulation is putting a written information security program (WISP) in place for all records containing personal information on residents of Massachusets, as well as monitoring third parties’ abilities to protect personal information. Once a company implements a plan, the legislation states that an employee or employees must be dedicated to maintaining and supervising its implication. It also requires ongoing employee training and procedures for maintaining employee compliance. 

The WISP must secure all records that contain personal information and put in place technical, administrative, and physical safeguards to protect ‘personal information’, which in the actual legislation is defined as:

“a Massachusets resident’s first name and last name or first initial and last name in combination with any one or more of the following data elements that relate to such resident: Social Security number, driver’s license number or state issued identification card number; or financial account number, or credit or debit card number, with or without any required security code, access code, personal identification number or password, that would permit access to a resident’s financial account; provided however, that “personal information” shall not include information that is lawfully obtained from publicly available information, or from federal, state or local government records lawfully available to the general public.”

In a nutshell, the legislation requires companies to do the following:

– limit the amount of personal information gathered, limit the amount of time the info is retained, and limit the individuals who have access to personal information to such that is necessary to accomplish an intended purpose.

– determine the location of all records that contain personal information, whether it be on laptops, paper, or other storage devices and secure all areas/storage devices that contain these records.

– impose detailed, written restrictions on access to the records

– regular monitoring of the information security system including upgrading info safeguards to limit risks

– annual review of the scope of security measures or a review when business practices concerning security change

– documentation of actions taken in response to breaches of information security and, upon review, necessary security changes made concerning the breach.

In part two of this post, we will review computer system requirements.

Link to original post

Share This Article
Facebook Pinterest LinkedIn
Share

Follow us on Facebook

Latest News

street address database
Why Data-Driven Companies Rely on Accurate Street Address Databases
Big Data Exclusive
predictive analytics risk management
How Predictive Analytics Is Redefining Risk Management Across Industries
Analytics Exclusive Predictive Analytics
data analytics and gold trading
Data Analytics and the New Era of Gold Trading
Analytics Big Data Exclusive
student learning AI
Advanced Degrees Still Matter in an AI-Driven Job Market
Artificial Intelligence Exclusive

Stay Connected

1.2kFollowersLike
33.7kFollowersFollow
222FollowersPin

You Might also Like

online advertising
Artificial IntelligenceMarketing

AI Tools to Help You with Your Online Advertising Spend

5 Min Read
Image
AnalyticsBig DataBusiness IntelligenceCloud ComputingData MiningData VisualizationData WarehousingHadoopITMapReduceOpen SourceSoftwareUnstructured Data

3 Reasons Hadoop is Heading to the Cloud

5 Min Read
smart data for business cost reduction
Big Data

3 Massive Cost-Saving Benefits of Smart Data for Businesses

4 Min Read

social CRM (sCRM) definition : CRM + aggregator + socialytics

6 Min Read

SmartData Collective is one of the largest & trusted community covering technical content about Big Data, BI, Cloud, Analytics, Artificial Intelligence, IoT & more.

AI chatbots
AI Chatbots Can Help Retailers Convert Live Broadcast Viewers into Sales!
Chatbots
ai is improving the safety of cars
From Bolts to Bots: How AI Is Fortifying the Automotive Industry
Artificial Intelligence

Quick Link

  • About
  • Contact
  • Privacy
Follow US
© 2008-25 SmartData Collective. All Rights Reserved.
Go to mobile version
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?