summary
Introduced
04/15/2015
04/15/2015
In Committee
03/21/2016
03/21/2016
Crossed Over
Passed
Dead
07/31/2016
07/31/2016
Introduced Session
189th General Court
Bill Summary
For legislation relative to the security of personal financial information. Consumer Protection and Professional Licensure.
AI Summary
This bill amends existing Massachusetts law, Chapter 93H, to strengthen the security of personal financial information by updating definitions and adding new provisions. Key changes include defining terms like "access device" (e.g., credit or debit cards), "breach of security" (unauthorized access or use of data that risks identity theft or fraud), and "encrypted" (data transformed to be unreadable without a key, with a minimum standard of 128-bit encryption). The bill also clarifies that notice of a breach can be provided electronically or through substitute means if traditional methods are impractical. Importantly, it prohibits businesses that accept payment cards from retaining sensitive data like card security codes or full magnetic stripe data after a transaction is authorized, with a 48-hour exception for PIN debit transactions, and makes businesses liable for costs incurred by financial institutions to protect cardholders in the event of a breach. Finally, it allows businesses to comply with federal data security regulations if they also notify Massachusetts residents, the Attorney General, and the Director of the Office of Consumer Affairs and Business Regulation of any breaches.
Committee Categories
Budget and Finance, Labor and Employment
Sponsors (1)
Last Action
Bill reported favorably by committee and referred to the committee on Senate Ways and Means (on 03/21/2016)
Official Document
bill text
bill summary
Loading...
bill summary
Loading...
bill summary
| Document Type | Source Location |
|---|---|
| State Bill Page | https://malegislature.gov/Bills/189/S184 |
| Bill | https://malegislature.gov/Bills/189/S184.pdf |
Loading...