USPrivacyAtlasState Privacy & Data Security Law Matcher

State Guide

Massachusetts Privacy & Data Security Laws

Every statute below can apply to a business handling Massachusetts residents' data, depending on your revenue, the number of Massachusetts consumers you process, and what kind of data you collect. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.

Data Security & Breach Notification · 1

Varies by state
Massachusetts data breach notification law
MA Breach Notification

Requires a comprehensive Written Information Security Program (WISP) — one of the most prescriptive state security regulations. Applies regardless of company size whenever you hold covered personal information about a resident of this state.

Mass. Gen. Laws ch. 93H; 201 Mass. Code Regs. 17.00Read statute →

On the Horizon — Proposed, Not Yet Law · 1

Massachusetts
Massachusetts comprehensive data privacy bill

Still the state most likely to flip to enacted next — it has cleared both chambers unanimously, and only House/Senate reconciliation stands between it and the Governor. The two versions differ enough that the conference has now run past two months.

Status: Senate passed S.2619 40-0 (Sep 25, 2025); House passed its own version, H.5479, 146-0 (Jun 4, 2026); the Senate non-concurred in the House amendment and appointed its conferees Jun 11, 2026, and the House insisted on its amendment and appointed its conferees Jun 17, 2026, seating a six-member conference committee (Sens. Creem, Finegold, O'Connor; Reps. Moran, Farley-Bouvier, Vieira). The committee was still meeting as of a public session on Jul 30, 2026 and has not reported out a reconciled bill. Nothing has reached Gov. Healey's desk. Re-verified against malegislature.gov Sep 11, 2026 — the bill history ends at the Jun 17, 2026 House conference appointment.