Bill

Bill > S184


MA S184

MA S184
Relative to the security of personal financial information


summary

Introduced
04/15/2015
In Committee
03/21/2016
Crossed Over
Passed
Dead
07/31/2016

Introduced Session

189th General Court

Bill Summary

For legislation relative to the security of personal financial information. Consumer Protection and Professional Licensure.

AI Summary

This bill amends existing Massachusetts law, Chapter 93H, to strengthen the security of personal financial information by updating definitions and adding new provisions. Key changes include defining terms like "access device" (e.g., credit or debit cards), "breach of security" (unauthorized access or use of data that risks identity theft or fraud), and "encrypted" (data transformed to be unreadable without a key, with a minimum standard of 128-bit encryption). The bill also clarifies that notice of a breach can be provided electronically or through substitute means if traditional methods are impractical. Importantly, it prohibits businesses that accept payment cards from retaining sensitive data like card security codes or full magnetic stripe data after a transaction is authorized, with a 48-hour exception for PIN debit transactions, and makes businesses liable for costs incurred by financial institutions to protect cardholders in the event of a breach. Finally, it allows businesses to comply with federal data security regulations if they also notify Massachusetts residents, the Attorney General, and the Director of the Office of Consumer Affairs and Business Regulation of any breaches.

Committee Categories

Budget and Finance, Labor and Employment

Sponsors (1)

Last Action

Bill reported favorably by committee and referred to the committee on Senate Ways and Means (on 03/21/2016)

bill text


bill summary

Loading...

bill summary

Loading...

bill summary

Loading...