"Encrypted," the transformation of data through the use of an algorithmic process, or analternative method at least as secure, into a form in which meaning cannot be assigned withoutthe use of a confidential process or key, unless further defined by regulation by the office of consumer affairs and business regulation.“Person,” a natural person, corporation, association, partnership or other legal entity, other thanan agency, executive office, department, board, commission, bureau, division or authority of theCommonwealth, or any of its branches, or any political subdivision thereof."Personal information," a Massachusetts resident's first name and last name or first initial andlast name in combination with any one or more of the following data elements that relate to suchresident: (a) Social Security number; (b) driver's license number or state-issued identificationcard number; or (c) financial account number, or credit or debit card number, with or withoutany required security code, access code, personal identification number or password, that wouldpermit access to a resident’s financial account; provided, however, that “Personal information”shall not include information that is lawfully obtained from publicly available information, orfrom federal, state or local government records lawfully made available to the general public.“Record” or “Records,” any material upon which written, drawn, spoken, visual, orelectromagnetic information or images are recorded or preserved, regardless of physical form orcharacteristics.17.03:
Duty to Protect and Standards for Protecting Personal Information
Every person that owns, licenses, stores or maintains personal information about a resident of theCommonwealth shall develop, implement, maintain and monitor a comprehensive, writteninformation security program applicable to any records containing such personalinformation. Such comprehensive information security program shall be reasonably consistentwith industry standards, and shall contain administrative, technical, and physical safeguards toensure the security and confidentiality of such records. Moreover, the safeguards contained insuch program must be consistent with the safeguards for protection of personal information andinformation of a similar character set forth in any state or federal regulations by which the personwho owns, licenses, stores or maintains such information may be regulated.Whether the comprehensive information security program is in compliance with theseregulations for the protection of personal information, whether pursuant to section 17.03 or 17.04hereof, shall be evaluated taking into account (i) the size, scope and type of business of theperson obligated to safeguard the personal information under such comprehensive informationsecurity program, (ii) the amount of resources available to such person, (iii) the amount of storeddata, and (iv) the need for security and confidentiality of both consumer and employeeinformation. Without limiting the generality of the foregoing, every comprehensive informationsecurity program shall include, but shall not be limited to:(a) Designating one or more employees to maintain the comprehensive information securityprogram;2
Add a Comment