Massachusetts standards for protecting personal information
201 CMR 17.00 · Read 2026-08-15
In force since 2010 and still the most prescriptive state security regulation, with a written information security program required in text.
Identifier
- Identifier
- 201 CMR 17.00
- Level
- State MA
- Status
- In force
- Adopted
- 2009-11-04
- Applies from
- 2010-03-01
- Supervisory bodies
- Massachusetts OCABR
Named requirements
Written information security program
201 CMR 17.03
A documented program with named responsibility, risk assessment, training and annual review.
Third party service providers
201 CMR 17.03(2)(f)
Selection of providers able to protect personal information, with the duty written into the contract.
Encryption
201 CMR 17.04(3)
Encryption of personal information transmitted across public networks and stored on portable devices.
Official source
Change monitoring
The row is re-read against the publisher's own publication on a fixed interval. The dates below can be checked on the spot and travel with the API response.
| Field | Value |
|---|---|
| Register | Massachusetts OCABR — 201 CMR 17.00 |
| Publisher | Massachusetts Office of Consumer Affairs and Business Regulation |
| Last read | 2026-08-15 |
| Interval | Every 30 days |
| Next re-read | 2026-09-14 |
| Status | Checked against the publisher |
Row history
Dated events concerning this exact row, newest first. No event appears here without a date in a primary source.
| Date | Event | Source |
|---|---|---|
| 2026-08-15 | Row read against the official publication | Massachusetts Office of Consumer Affairs and Business Regulation |
| 2010-03-01 | Date of application according to the publisher | Massachusetts Office of Consumer Affairs and Business Regulation |
| 2009-11-04 | Adopted under 201 CMR 17.00 | Massachusetts Office of Consumer Affairs and Business Regulation |
Monitoring states when the row was checked, not how the legal position should be assessed.
Cite this row
The string below travels with a memo, a case file or an agent chain. The same string sits in the citation field of the API response.
201 CMR 17.00, Massachusetts standards for protecting personal information. ExploreWorld Legal, https://legal.exploreworldai.com/us/regler/massachusetts-data-security (hämtad 2026-08-25, bevis sha256:2742fbf784dc5a3a, bygge legal-2026-08-25).
- sha256:
- 2742fbf784dc5a3aef8b4bcbedfe2cf6344fdc51d1ab005a43efe5031734f894
- hämtad:
- 2026-08-25
- source_confidence:
- derived
- bygge:
- legal-2026-08-25
Derived path to the publisher. The address is built from the identifier and lands in the publisher's own register. mass.gov.
The row is a source reference with an official identifier. No legal advice and no compliance decision.
Verifiable trust signals
- Six fixed blocks, one source per line
- No sentence written by a language model
- Engine version and read date on every answer
- No customer data, no documents, no advice
- Model card and audit published under the EU AI Act