Massachusetts Data Privacy Law in Effect Jan. 1, 2009
Massachusetts is requiring a long list of security practices of companies with customers in Massachusetts.
The law covers both business practices and technical issues, including:
- establishing risk management practices
- establishing employee training
- creating policies governing handling of personal data
- verifying third party providers can protect personal data
- documenting data breaches and changes in business practices
- encrypt personal data on laptops and mobile devices
States have long been at the forefront of privacy protection in the U.S., sometimes through legislation like this and sometimes through Attorneys General offices as in Connecticut's response to a Bank of New York Mellon breach earlier this year.
More on the Massachusetts law at CIO.



Email This!
Digg it!
Del.icio.us
Reddit!
Newsvine
