Massachusetts H358 mandates information security programs for entities handling personal financial information of residents.
Massachusetts H358 requires entities that own or license personal information about residents to develop, implement, and maintain a comprehensive information security program. This program must include administrative, technical, and physical safeguards to protect personal information from unauthorized access, use, or disclosure. The Department of Consumer Affairs and Business Regulation will adopt regulations to ensure these programs are effective. The bill also outlines the definition of personal information, breach of security, and notice requirements in case of a security breach.
Included in complete analysis
- Overview
- Core Provisions
- Implementation
- Impact
- Legal Framework
- Critical Issues
See what it does, who it affects, and the critical issues in plain language. Free, 30 seconds.