Mass. passes tough data security law.

PositionDATA SECURITY

[ILLUSTRATION OMITTED]

Massachusetts has passed stringent data privacy and security regulations that may influence the practices and policies of companies nationwide.

As of January 1, Massachusetts requires businesses that collect information about that state's residents to encrypt sensitive data stored on laptop computers and other portable devices. Michigan and Washington state are considering similar regulations.

The Massachusetts law, executive order 504, requires businesses to meet a list of minimum standards. For example, all organizations that collect personal data from or about Massachusetts residents must adopt a comprehensive written security program, conduct internal and external security reviews, and complete employee training regarding their programs, according to Network World. The security program must:

* Designate one or more employees to maintain the security program

* Identify and assess the internal and external risks to the security, confidentiality, and/or integrity of any electronic, paper, or other records containing personal information

* Evaluate current safeguards and procedures for detecting and preventing security system failures

* Implement and evaluate ongoing employee training (which must include temporary and contract employees)

* Implement and evaluate employee compliance with policies and procedures

* Develop security policies that establish whether and how employees should be allowed to keep, access, and transport records containing personal information outside of business premises

Legal experts say...

To continue reading

Request your trial

VLEX uses login cookies to provide you with a better browsing experience. If you click on 'Accept' or continue browsing this site we consider that you accept our cookie policy. ACCEPT