WHAT THIS BILL REGULATES · 4 REQUIREMENT TYPES
How Is This Bill Enforced
Verbatim statutory text on the left; plain-language analysis and a per-section checklist on the right. Numbered markers cross-link to the matching checklist row.
(a)(1)–(35) As used in this chapter, the following words shall, unless the context clearly requires otherwise, have the following meanings: (1) "authentication", the process of verifying an individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) or entity for security purposes. (2) "chapter", this chapter of the General Laws, as from time to time may be amended, and any regulations promulgated under said chapter. (3) "collect" and "collection", buying, renting, licensing, gathering, obtaining, receiving, accessing, or otherwise acquiring covered dataCovered data"covered data", information, including derived data, inferences, and unique persistent identifiers that identifies or is linked or reasonably linkable, alone or in combination with other information, to an individual or a device that identifies or is linked or reasonably linkable to an individual. However, the term "covered data" does not include de-identified data or publicly available information.Ch. 93N § 1(a)(6) by any means. (4) "consentConsent"consent", a clear affirmative act signifying an individual's freely given, specific, informed, and unambiguous agreement to allow the processing of specific categories of personal information relating to the individual for a narrowly defined particular purpose after having been informed, in response to a specific request from a covered entity that meets the requirements of this chapter; provided, however, that "consent" may include a written statement, including a statement written by electronic means, or any other unambiguous affirmative action; and provided further, that the following shall not constitute "consent": (i) acceptance of a general or broad terms of use or similar document that contains descriptions of personal information processing along with other, unrelated information; (ii) hovering over, muting, pausing, or closing a given piece of content; or (iii) agreement obtained through dark patterns or a false, fictitious, fraudulent, or materially misleading statement or representation.Ch. 93N § 1(a)(4)", a clear affirmative act signifying an individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14)'s freely given, specific, informed, and unambiguous agreement to allow the processing of specific categories of personal information relating to the individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) for a narrowly defined particular purpose... (5) "control"... (6) "covered dataCovered data"covered data", information, including derived data, inferences, and unique persistent identifiers that identifies or is linked or reasonably linkable, alone or in combination with other information, to an individual or a device that identifies or is linked or reasonably linkable to an individual. However, the term "covered data" does not include de-identified data or publicly available information.Ch. 93N § 1(a)(6)"... (7) "covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7)"... (8) "covered high-impact social media companyCovered high-impact social media company"covered high-impact social media company", a covered entity that provides any internet-accessible platform where: (i) such covered entity generates $3,000,000,000 or more in annual revenue; (ii) such platform has 300,000,000 or more monthly active users for not fewer than 3 of the preceding 12 months on the online product or service of such covered entity; and (iii) such platform constitutes an online product or service that is primarily used by users to access or share user-generated content.Ch. 93N § 1(a)(8)"... (9) "dark pattern or deceptive designDark pattern or deceptive design"dark pattern or deceptive design", a user interface that is designed, modified, or manipulated with the purpose or substantial effect of obscuring, subverting, or impairing a reasonable individual's autonomy, decision-making, or choice, including, but not limited to, any practice the Federal Trade Commission refers to as a "dark pattern."Ch. 93N § 1(a)(9)"... (10) "de-identified dataDe-identified data"de-identified data", information that does not identify and is not linked or reasonably linkable to a distinct individual or a device, regardless of whether the information is aggregated, and if the covered entity or service provider: (i) takes technical measures to ensure that the information cannot, at any point, be used to re-identify any individual or device that identifies or is linked or reasonably linkable to an individual; (ii) publicly commits in a clear and conspicuous manner: (A) to process and transfer the information solely in a de-identified form without any reasonable means for re-identification; and (B) to not attempt to re-identify the information with any individual or device that identifies or is linked or reasonably linkable to an individual; and (iii) contractually obligates any person or entity that receives the information from the covered entity or service provider: (A) to comply with all the provisions of this paragraph with respect to the information; and (B) to require that such contractual obligations be included contractually in all subsequent instances for which the data may be received.Ch. 93N § 1(a)(10)"... (11) "derived data"... (12) "device"... (13) "homepage"... (14) "individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14)"... (15) "knowledgeKnowledge"knowledge", (i) with respect to a covered entity that is a covered high-impact social media company, the entity knew or should have known the individual was a minor; (ii) with respect to a covered entity or service provider that is a large data holder, and otherwise is not a covered high-impact social media company, that the covered entity knew or acted in willful disregard of the fact that the individual was a minor; and (iii) with respect to a covered entity or service provider that does not meet the requirements of clause (i) or (ii), actual knowledge.Ch. 93N § 1(a)(15)"... (16) "large data holderLarge data holder"large data holder", a covered entity or service provider that in the most recent calendar year: (i) had annual gross revenues of $200,000,000 or more; and (ii) collected, processed, or transferred the covered data of more than 2,000,000 individuals or devices that identify or are linked or reasonably linkable to one or more individuals, excluding covered data collected and processed solely for the purpose of initiating, rendering, billing for, finalizing, completing, or otherwise collecting payment for a requested product or service; or the sensitive covered data of more than 200,000 individuals or devices that identify or are linked or reasonably linkable to one or more individuals. The term "large data holder" does not include any instance in which the covered entity or service provider would qualify as a large data holder solely on the basis of collecting or processing personal email addresses, personal telephone numbers, or log-in information of an individual or device to allow the individual or device to log in to an account administered by the covered entity or service provider.Ch. 93N § 1(a)(16)"... (17) "material"... (18) "minorMinor"minor", an individual under the age of 18.Ch. 93N § 1(a)(18)"... (19) "neural dataNeural data"neural data", means information that is generated by measuring the activity of an individual's central or peripheral nervous system, and that is not inferred from non-neural information.Ch. 93N § 1(a)(19)"... (20) "OCABR"... (21) "precise geolocation information"... (22) "process"... (23) "processing purpose"... (24) "profilingProfiling"profiling", any form of automated processing performed on personal data to evaluate, analyze or predict personal aspects related to an identified or identifiable individual's economic situation, health, personal preferences, interests, reliability, behavior, location or movements.Ch. 93N § 1(a)(24)"... (25) "publicly available information"... (26) "reasonably understandable"... (27) "sensitive covered dataSensitive covered data"sensitive covered data", a form of covered data, including neural data. (i) neural data; (ii) covered data processed from neural data concerning an individual's past, present or future mental or physical health condition, disability, diagnosis or treatment, including pregnancy and cosmetic treatment;Ch. 93N § 1(a)(27)"... (28) "service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28)"... (29) "service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) data"... (30) "targeted advertisingTargeted advertising"targeted advertising", presenting to an individual or device identified by a unique identifier, or groups of individuals or devices identified by unique identifiers, an online advertisement that is selected based on known or predicted preferences, characteristics, or interests associated with the individual or a device identified by a unique identifier; provided, however, that "targeted advertising" does not include: (i) advertising or marketing to an individual or an individual's device in response to the individual's specific request for information or feedback; (ii) contextual advertising, which is when an advertisement is displayed based on the content with or in which the advertisement appears and does not vary based on who is viewing the advertisement; or (iii) processing covered data strictly necessary for the sole purpose of measuring or reporting advertising or content performance, reach, or frequency, including independent measurement.Ch. 93N § 1(a)(30)"... (31) "third partyThird party"third party", any person or entity, including a covered entity, that (i) collects, processes, or transfers covered data and is not a consumer-facing business with which the individual linked or reasonably linkable to such covered data expects and intends to interact; and (ii) is not a service provider with respect to such data. This term does not include a person or entity that collects covered data from another entity if the two entities are related by common ownership or corporate control, but only if a reasonable consumer's reasonable expectation would be that such entities share information.Ch. 93N § 1(a)(31)"... (32) "third partyThird party"third party", any person or entity, including a covered entity, that (i) collects, processes, or transfers covered data and is not a consumer-facing business with which the individual linked or reasonably linkable to such covered data expects and intends to interact; and (ii) is not a service provider with respect to such data. This term does not include a person or entity that collects covered data from another entity if the two entities are related by common ownership or corporate control, but only if a reasonable consumer's reasonable expectation would be that such entities share information.Ch. 93N § 1(a)(31) data"... (33) "transfer"... (34) "unique identifier"... (35) "widely distributed media"...
Section 1 establishes the definitional framework for the entire chapter. The most consequential definition is neural data — information generated by measuring the activity of an individual's central or peripheral nervous system, expressly excluding inferences from non-neural information. Neural data is categorized as sensitive covered data, which triggers heightened protections throughout the bill. The section also defines the entities subject to the chapter: covered entities (data controllers), service providers (data processors), large data holders (entities with ≥$200M revenue and ≥2M individuals' data), and covered high-impact social media companies ($3B+ revenue, 300M+ monthly users). The tiered knowledge standard for minor status is notable — ranging from constructive knowledge for social media companies to actual knowledge for smaller entities.
(a)(1) 1 A covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) or service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) shall not: (1) collect or process sensitive covered dataSensitive covered data"sensitive covered data", a form of covered data, including neural data. (i) neural data; (ii) covered data processed from neural data concerning an individual's past, present or future mental or physical health condition, disability, diagnosis or treatment, including pregnancy and cosmetic treatment;Ch. 93N § 1(a)(27), except where such collection or processing is strictly necessary to provide or maintain a specific product or service requested by the individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) to whom the covered dataCovered data"covered data", information, including derived data, inferences, and unique persistent identifiers that identifies or is linked or reasonably linkable, alone or in combination with other information, to an individual or a device that identifies or is linked or reasonably linkable to an individual. However, the term "covered data" does not include de-identified data or publicly available information.Ch. 93N § 1(a)(6) pertains.
(a)(2) 2 transfer an individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14)'s sensitive covered dataSensitive covered data"sensitive covered data", a form of covered data, including neural data. (i) neural data; (ii) covered data processed from neural data concerning an individual's past, present or future mental or physical health condition, disability, diagnosis or treatment, including pregnancy and cosmetic treatment;Ch. 93N § 1(a)(27) to a third partyThird party"third party", any person or entity, including a covered entity, that (i) collects, processes, or transfers covered data and is not a consumer-facing business with which the individual linked or reasonably linkable to such covered data expects and intends to interact; and (ii) is not a service provider with respect to such data. This term does not include a person or entity that collects covered data from another entity if the two entities are related by common ownership or corporate control, but only if a reasonable consumer's reasonable expectation would be that such entities share information.Ch. 93N § 1(a)(31), unless: (i) the transfer is made pursuant to the consent of the individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14), given before each specific transfer takes place; (ii) the transfer is necessary to comply with a legal obligation imposed by federal law, so long as such obligation preexisted the collection and previous notice of such obligation was provided to the individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) to whom the data pertains; (iii) the transfer is necessary to prevent an individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) from imminent injury where the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) believes in good faith that the individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) is at risk of death, serious physical injury, or serious health risk;
(a)(3) 3 process sensitive covered dataSensitive covered data"sensitive covered data", a form of covered data, including neural data. (i) neural data; (ii) covered data processed from neural data concerning an individual's past, present or future mental or physical health condition, disability, diagnosis or treatment, including pregnancy and cosmetic treatment;Ch. 93N § 1(a)(27) for the purposes of targeted advertisingTargeted advertising"targeted advertising", presenting to an individual or device identified by a unique identifier, or groups of individuals or devices identified by unique identifiers, an online advertisement that is selected based on known or predicted preferences, characteristics, or interests associated with the individual or a device identified by a unique identifier; provided, however, that "targeted advertising" does not include: (i) advertising or marketing to an individual or an individual's device in response to the individual's specific request for information or feedback; (ii) contextual advertising, which is when an advertisement is displayed based on the content with or in which the advertisement appears and does not vary based on who is viewing the advertisement; or (iii) processing covered data strictly necessary for the sole purpose of measuring or reporting advertising or content performance, reach, or frequency, including independent measurement.Ch. 93N § 1(a)(30).
Section 2 imposes strict limitations on the collection, processing, and transfer of sensitive covered data — which includes all neural data. Covered entities and service providers may collect or process sensitive covered data only where strictly necessary to provide or maintain a specific product or service requested by the individual. Transfers to third parties require per-transfer affirmative consent, with narrow exceptions for legal compliance and imminent-injury scenarios. The section categorically prohibits processing sensitive covered data for targeted advertising.
(a)(1)–(4) 4 A covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) shall provide an individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14), after receiving a verified request from the individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14), with the right to: (1) access: (i) in a human-readable format that a reasonable individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) can understand and download from the internet and transmit freely, the covered dataCovered data"covered data", information, including derived data, inferences, and unique persistent identifiers that identifies or is linked or reasonably linkable, alone or in combination with other information, to an individual or a device that identifies or is linked or reasonably linkable to an individual. However, the term "covered data" does not include de-identified data or publicly available information.Ch. 93N § 1(a)(6) (except covered dataCovered data"covered data", information, including derived data, inferences, and unique persistent identifiers that identifies or is linked or reasonably linkable, alone or in combination with other information, to an individual or a device that identifies or is linked or reasonably linkable to an individual. However, the term "covered data" does not include de-identified data or publicly available information.Ch. 93N § 1(a)(6) in a back-up or archival system) of the individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) making the request that is collected, processed, or transferred by the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) or any service provider of the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) within the 12 months preceding the request; (ii) the categories of any third partyThird party"third party", any person or entity, including a covered entity, that (i) collects, processes, or transfers covered data and is not a consumer-facing business with which the individual linked or reasonably linkable to such covered data expects and intends to interact; and (ii) is not a service provider with respect to such data. This term does not include a person or entity that collects covered data from another entity if the two entities are related by common ownership or corporate control, but only if a reasonable consumer's reasonable expectation would be that such entities share information.Ch. 93N § 1(a)(31) or service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28), if applicable, and an option for consumers to obtain the names of any such third partyThird party"third party", any person or entity, including a covered entity, that (i) collects, processes, or transfers covered data and is not a consumer-facing business with which the individual linked or reasonably linkable to such covered data expects and intends to interact; and (ii) is not a service provider with respect to such data. This term does not include a person or entity that collects covered data from another entity if the two entities are related by common ownership or corporate control, but only if a reasonable consumer's reasonable expectation would be that such entities share information.Ch. 93N § 1(a)(31) as well as and the categories of any service providersService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) to whom the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) has transferred the covered data of the individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14), as well as the categories of sources from which the covered dataCovered data"covered data", information, including derived data, inferences, and unique persistent identifiers that identifies or is linked or reasonably linkable, alone or in combination with other information, to an individual or a device that identifies or is linked or reasonably linkable to an individual. However, the term "covered data" does not include de-identified data or publicly available information.Ch. 93N § 1(a)(6) was collected; and (2) correct any verifiable substantial inaccuracy or substantially incomplete information with respect to the covered data of the individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) that is processed by the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) and instruct the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) to make reasonable efforts to notify all third parties or service providersService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) to which the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) transferred such covered data of the corrected information; (3) delete covered data of the individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) that is processed by the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) and instruct the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) to make reasonable efforts to notify all third parties or service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) to which the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) transferred such covered data of the individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14)'s deletion request; and (4) to the extent technically feasible, export to the individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) or directly to another entity the covered data of the individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) that is processed by the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7), including inferences linked or reasonably linkable to the individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) but not including other derived data, without licensing restrictions that limit such transfers in: (i) a human-readable format that a reasonable individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) can understand and download from the internet and transmit freely; and (ii) a portable, structured, interoperable, and machine-readable format.
(b)–(l) 4 A covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) may not condition, effectively condition, attempt to condition, or attempt to effectively condition the exercise of a right described in subsection (a) through: (1) the use of any false, fictitious, fraudulent, or materially misleading statement or representation; or (2) the use of any dark pattern or deceptive designDark pattern or deceptive design"dark pattern or deceptive design", a user interface that is designed, modified, or manipulated with the purpose or substantial effect of obscuring, subverting, or impairing a reasonable individual's autonomy, decision-making, or choice, including, but not limited to, any practice the Federal Trade Commission refers to as a "dark pattern."Ch. 93N § 1(a)(9). (c) Subject to subsections (d) and (e), each request under subsection (a) shall be completed within 45 days of such request from an individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14), unless it is demonstrably impracticable or impracticably costly to verify such individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14)'s request. (d) A response period set forth in this subsection may be extended once by 20 additional days when reasonably necessary... (e) A covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7): (1) shall provide an individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) with the opportunity to exercise each of the rights described in subsection (a) and with respect to: (i) the first two times that an individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) exercises any right described in subsection (a) in any 12-month period, shall allow the individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) to exercise such right free of charge... (f) A covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) may not permit an individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) to exercise a right described in subsection (a), in whole or in part, if the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7): (1) cannot reasonably verify that the individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) making the request to exercise the right is the individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) whose covered dataCovered data"covered data", information, including derived data, inferences, and unique persistent identifiers that identifies or is linked or reasonably linkable, alone or in combination with other information, to an individual or a device that identifies or is linked or reasonably linkable to an individual. However, the term "covered data" does not include de-identified data or publicly available information.Ch. 93N § 1(a)(6) is the subject of the request... (g) If a covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) cannot reasonably verify that a request to exercise a right described in subsection (a) is made by the individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) whose covered dataCovered data"covered data", information, including derived data, inferences, and unique persistent identifiers that identifies or is linked or reasonably linkable, alone or in combination with other information, to an individual or a device that identifies or is linked or reasonably linkable to an individual. However, the term "covered data" does not include de-identified data or publicly available information.Ch. 93N § 1(a)(6) is the subject of the request, the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7): (1) may request that the individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) making the request to exercise the right provide any additional information necessary for the sole purpose of verifying the identity of the individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14); and (2) may not process or transfer such additional information for any other purpose. (h) A covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) may decline, with adequate explanation to the individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14), to comply with a request to exercise a right described in subsection (a), in whole or in part, that would: (1) require the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) to retain any covered dataCovered data"covered data", information, including derived data, inferences, and unique persistent identifiers that identifies or is linked or reasonably linkable, alone or in combination with other information, to an individual or a device that identifies or is linked or reasonably linkable to an individual. However, the term "covered data" does not include de-identified data or publicly available information.Ch. 93N § 1(a)(6) collected for a single, one-time transaction... (i) A covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) may decline, with adequate explanation to the individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14), to comply with a request for deletion pursuant to paragraph (3) of subsection (a) if such request: (1) unreasonably interferes with the provision of products or services... (j) In a circumstance that would allow a denial pursuant to this section, a covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) shall partially comply with the remainder of the request if it is possible and not unduly burdensome to do so. (k) The receipt of a large number of verified requests, on its own, may not be considered to render compliance with a request demonstrably impracticable. (l) A covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) shall facilitate the ability of individualsIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) to make requests under subsection (a) in any language in which the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) provides a product or service...
Section 3 establishes a comprehensive set of individual data rights: access (in human-readable and machine-readable formats), correction, deletion, and data portability. Requests must be fulfilled within 45 days, extendable by 20 days for complex requests. The first two exercises per 12-month period must be free of charge. The section also provides extensive exceptions allowing covered entities to decline requests — including for trade secrets, fraud prevention, professional ethical obligations, and where compliance would be impracticable. Covered entities must facilitate requests in all languages in which they offer products and ensure accessibility for individuals with disabilities.
(a)(1)–(9) 5 The requirements of this chapter with respect to a request for consentConsent"consent", a clear affirmative act signifying an individual's freely given, specific, informed, and unambiguous agreement to allow the processing of specific categories of personal information relating to the individual for a narrowly defined particular purpose after having been informed, in response to a specific request from a covered entity that meets the requirements of this chapter; provided, however, that "consent" may include a written statement, including a statement written by electronic means, or any other unambiguous affirmative action; and provided further, that the following shall not constitute "consent": (i) acceptance of a general or broad terms of use or similar document that contains descriptions of personal information processing along with other, unrelated information; (ii) hovering over, muting, pausing, or closing a given piece of content; or (iii) agreement obtained through dark patterns or a false, fictitious, fraudulent, or materially misleading statement or representation.Ch. 93N § 1(a)(4) from a covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) or service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) to an individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) are the following: (1) The request for consentConsent"consent", a clear affirmative act signifying an individual's freely given, specific, informed, and unambiguous agreement to allow the processing of specific categories of personal information relating to the individual for a narrowly defined particular purpose after having been informed, in response to a specific request from a covered entity that meets the requirements of this chapter; provided, however, that "consent" may include a written statement, including a statement written by electronic means, or any other unambiguous affirmative action; and provided further, that the following shall not constitute "consent": (i) acceptance of a general or broad terms of use or similar document that contains descriptions of personal information processing along with other, unrelated information; (ii) hovering over, muting, pausing, or closing a given piece of content; or (iii) agreement obtained through dark patterns or a false, fictitious, fraudulent, or materially misleading statement or representation.Ch. 93N § 1(a)(4) shall be provided to the individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) in a clear and conspicuous standalone disclosure made through the primary medium used to offer the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7)'s product or service... (2) The request includes a description of the processing purpose for which the individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14)'s consentConsent"consent", a clear affirmative act signifying an individual's freely given, specific, informed, and unambiguous agreement to allow the processing of specific categories of personal information relating to the individual for a narrowly defined particular purpose after having been informed, in response to a specific request from a covered entity that meets the requirements of this chapter; provided, however, that "consent" may include a written statement, including a statement written by electronic means, or any other unambiguous affirmative action; and provided further, that the following shall not constitute "consent": (i) acceptance of a general or broad terms of use or similar document that contains descriptions of personal information processing along with other, unrelated information; (ii) hovering over, muting, pausing, or closing a given piece of content; or (iii) agreement obtained through dark patterns or a false, fictitious, fraudulent, or materially misleading statement or representation.Ch. 93N § 1(a)(4) is sought by: (i) clearly stating the specific categories of covered dataCovered data"covered data", information, including derived data, inferences, and unique persistent identifiers that identifies or is linked or reasonably linkable, alone or in combination with other information, to an individual or a device that identifies or is linked or reasonably linkable to an individual. However, the term "covered data" does not include de-identified data or publicly available information.Ch. 93N § 1(a)(6) that the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) shall collect, process, and transfer necessary to effectuate the processing purpose; and (ii) including a prominent heading and is reasonably understandable so that an individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) can identify and understand the processing purpose for which consentConsent"consent", a clear affirmative act signifying an individual's freely given, specific, informed, and unambiguous agreement to allow the processing of specific categories of personal information relating to the individual for a narrowly defined particular purpose after having been informed, in response to a specific request from a covered entity that meets the requirements of this chapter; provided, however, that "consent" may include a written statement, including a statement written by electronic means, or any other unambiguous affirmative action; and provided further, that the following shall not constitute "consent": (i) acceptance of a general or broad terms of use or similar document that contains descriptions of personal information processing along with other, unrelated information; (ii) hovering over, muting, pausing, or closing a given piece of content; or (iii) agreement obtained through dark patterns or a false, fictitious, fraudulent, or materially misleading statement or representation.Ch. 93N § 1(a)(4) is sought and the covered dataCovered data"covered data", information, including derived data, inferences, and unique persistent identifiers that identifies or is linked or reasonably linkable, alone or in combination with other information, to an individual or a device that identifies or is linked or reasonably linkable to an individual. However, the term "covered data" does not include de-identified data or publicly available information.Ch. 93N § 1(a)(6) to be collected, processed, or transferred by the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) for such processing purpose; (3) The request clearly explains the individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14)'s applicable rights related to consentConsent"consent", a clear affirmative act signifying an individual's freely given, specific, informed, and unambiguous agreement to allow the processing of specific categories of personal information relating to the individual for a narrowly defined particular purpose after having been informed, in response to a specific request from a covered entity that meets the requirements of this chapter; provided, however, that "consent" may include a written statement, including a statement written by electronic means, or any other unambiguous affirmative action; and provided further, that the following shall not constitute "consent": (i) acceptance of a general or broad terms of use or similar document that contains descriptions of personal information processing along with other, unrelated information; (ii) hovering over, muting, pausing, or closing a given piece of content; or (iii) agreement obtained through dark patterns or a false, fictitious, fraudulent, or materially misleading statement or representation.Ch. 93N § 1(a)(4); (4) The request is made in a manner reasonably accessible to and usable by individualsIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) with disabilities; (5) The request is made available to the individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) in each covered language in which the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) provides a product or service for which authorization is sought; (6) The option to refuse consentConsent"consent", a clear affirmative act signifying an individual's freely given, specific, informed, and unambiguous agreement to allow the processing of specific categories of personal information relating to the individual for a narrowly defined particular purpose after having been informed, in response to a specific request from a covered entity that meets the requirements of this chapter; provided, however, that "consent" may include a written statement, including a statement written by electronic means, or any other unambiguous affirmative action; and provided further, that the following shall not constitute "consent": (i) acceptance of a general or broad terms of use or similar document that contains descriptions of personal information processing along with other, unrelated information; (ii) hovering over, muting, pausing, or closing a given piece of content; or (iii) agreement obtained through dark patterns or a false, fictitious, fraudulent, or materially misleading statement or representation.Ch. 93N § 1(a)(4) shall be at least as prominent as the option to accept, and the option to refuse consentConsent"consent", a clear affirmative act signifying an individual's freely given, specific, informed, and unambiguous agreement to allow the processing of specific categories of personal information relating to the individual for a narrowly defined particular purpose after having been informed, in response to a specific request from a covered entity that meets the requirements of this chapter; provided, however, that "consent" may include a written statement, including a statement written by electronic means, or any other unambiguous affirmative action; and provided further, that the following shall not constitute "consent": (i) acceptance of a general or broad terms of use or similar document that contains descriptions of personal information processing along with other, unrelated information; (ii) hovering over, muting, pausing, or closing a given piece of content; or (iii) agreement obtained through dark patterns or a false, fictitious, fraudulent, or materially misleading statement or representation.Ch. 93N § 1(a)(4) shall take the same number of steps or fewer as the option to accept; (7) Processing or transferring any covered dataCovered data"covered data", information, including derived data, inferences, and unique persistent identifiers that identifies or is linked or reasonably linkable, alone or in combination with other information, to an individual or a device that identifies or is linked or reasonably linkable to an individual. However, the term "covered data" does not include de-identified data or publicly available information.Ch. 93N § 1(a)(6) collected pursuant to consentConsent"consent", a clear affirmative act signifying an individual's freely given, specific, informed, and unambiguous agreement to allow the processing of specific categories of personal information relating to the individual for a narrowly defined particular purpose after having been informed, in response to a specific request from a covered entity that meets the requirements of this chapter; provided, however, that "consent" may include a written statement, including a statement written by electronic means, or any other unambiguous affirmative action; and provided further, that the following shall not constitute "consent": (i) acceptance of a general or broad terms of use or similar document that contains descriptions of personal information processing along with other, unrelated information; (ii) hovering over, muting, pausing, or closing a given piece of content; or (iii) agreement obtained through dark patterns or a false, fictitious, fraudulent, or materially misleading statement or representation.Ch. 93N § 1(a)(4) for a different processing purpose than that for which consentConsent"consent", a clear affirmative act signifying an individual's freely given, specific, informed, and unambiguous agreement to allow the processing of specific categories of personal information relating to the individual for a narrowly defined particular purpose after having been informed, in response to a specific request from a covered entity that meets the requirements of this chapter; provided, however, that "consent" may include a written statement, including a statement written by electronic means, or any other unambiguous affirmative action; and provided further, that the following shall not constitute "consent": (i) acceptance of a general or broad terms of use or similar document that contains descriptions of personal information processing along with other, unrelated information; (ii) hovering over, muting, pausing, or closing a given piece of content; or (iii) agreement obtained through dark patterns or a false, fictitious, fraudulent, or materially misleading statement or representation.Ch. 93N § 1(a)(4) was obtained shall require consentConsent"consent", a clear affirmative act signifying an individual's freely given, specific, informed, and unambiguous agreement to allow the processing of specific categories of personal information relating to the individual for a narrowly defined particular purpose after having been informed, in response to a specific request from a covered entity that meets the requirements of this chapter; provided, however, that "consent" may include a written statement, including a statement written by electronic means, or any other unambiguous affirmative action; and provided further, that the following shall not constitute "consent": (i) acceptance of a general or broad terms of use or similar document that contains descriptions of personal information processing along with other, unrelated information; (ii) hovering over, muting, pausing, or closing a given piece of content; or (iii) agreement obtained through dark patterns or a false, fictitious, fraudulent, or materially misleading statement or representation.Ch. 93N § 1(a)(4) for the subsequent processing purpose; (8) The request for consentConsent"consent", a clear affirmative act signifying an individual's freely given, specific, informed, and unambiguous agreement to allow the processing of specific categories of personal information relating to the individual for a narrowly defined particular purpose after having been informed, in response to a specific request from a covered entity that meets the requirements of this chapter; provided, however, that "consent" may include a written statement, including a statement written by electronic means, or any other unambiguous affirmative action; and provided further, that the following shall not constitute "consent": (i) acceptance of a general or broad terms of use or similar document that contains descriptions of personal information processing along with other, unrelated information; (ii) hovering over, muting, pausing, or closing a given piece of content; or (iii) agreement obtained through dark patterns or a false, fictitious, fraudulent, or materially misleading statement or representation.Ch. 93N § 1(a)(4) must be displayed at or before the point of collection; and (9) The request must be accompanied by a copy of the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7)'s or service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28)'s privacy policy...
(b)–(c) 5 A covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) shall not infer that an individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) has provided consentConsent"consent", a clear affirmative act signifying an individual's freely given, specific, informed, and unambiguous agreement to allow the processing of specific categories of personal information relating to the individual for a narrowly defined particular purpose after having been informed, in response to a specific request from a covered entity that meets the requirements of this chapter; provided, however, that "consent" may include a written statement, including a statement written by electronic means, or any other unambiguous affirmative action; and provided further, that the following shall not constitute "consent": (i) acceptance of a general or broad terms of use or similar document that contains descriptions of personal information processing along with other, unrelated information; (ii) hovering over, muting, pausing, or closing a given piece of content; or (iii) agreement obtained through dark patterns or a false, fictitious, fraudulent, or materially misleading statement or representation.Ch. 93N § 1(a)(4) to a practice from the inaction of the individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) or the individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14)'s continued use of a service or product provided by the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7). (c) A covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) shall not obtain or attempt to obtain the consent of an individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) through: (1) the use of any false, fictitious, fraudulent, or materially misleading statement or representation; (2) the use of any dark pattern or deceptive designDark pattern or deceptive design"dark pattern or deceptive design", a user interface that is designed, modified, or manipulated with the purpose or substantial effect of obscuring, subverting, or impairing a reasonable individual's autonomy, decision-making, or choice, including, but not limited to, any practice the Federal Trade Commission refers to as a "dark pattern."Ch. 93N § 1(a)(9); or (3) conditioning or limiting access to an individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14)'s account.
Section 4 prescribes detailed requirements for how covered entities must obtain consent. Consent requests must be clear and conspicuous standalone disclosures, must specify the processing purpose and data categories, must explain the individual's rights, must be accessible and multilingual, and must present the option to refuse consent at least as prominently as the option to accept. Consent may not be inferred from inaction or continued use, and may not be obtained through dark patterns, misrepresentation, or by conditioning account access.
(a)(1)–(5) 6 A covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) or service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) shall establish, implement, and maintain reasonable policies, practices, and procedures that reflect the role of the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) or service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) in the collection, processing, and transferring of covered dataCovered data"covered data", information, including derived data, inferences, and unique persistent identifiers that identifies or is linked or reasonably linkable, alone or in combination with other information, to an individual or a device that identifies or is linked or reasonably linkable to an individual. However, the term "covered data" does not include de-identified data or publicly available information.Ch. 93N § 1(a)(6) and that: (1) consider applicable federal and state laws, rules, or regulations related to covered dataCovered data"covered data", information, including derived data, inferences, and unique persistent identifiers that identifies or is linked or reasonably linkable, alone or in combination with other information, to an individual or a device that identifies or is linked or reasonably linkable to an individual. However, the term "covered data" does not include de-identified data or publicly available information.Ch. 93N § 1(a)(6) the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) or service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) collects, processes, or transfers; (2) identify, assess, and mitigate privacy risks related to minorsMinor"minor", an individual under the age of 18.Ch. 93N § 1(a)(18); (3) mitigate privacy risks related to the products and services of the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) or the service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28), including in the design, development, and implementation of such products and services, considering the role of the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) or service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) and the information available to it; (4) evaluate the length of time that covered dataCovered data"covered data", information, including derived data, inferences, and unique persistent identifiers that identifies or is linked or reasonably linkable, alone or in combination with other information, to an individual or a device that identifies or is linked or reasonably linkable to an individual. However, the term "covered data" does not include de-identified data or publicly available information.Ch. 93N § 1(a)(6) shall be retained and circumstances under which covered dataCovered data"covered data", information, including derived data, inferences, and unique persistent identifiers that identifies or is linked or reasonably linkable, alone or in combination with other information, to an individual or a device that identifies or is linked or reasonably linkable to an individual. However, the term "covered data" does not include de-identified data or publicly available information.Ch. 93N § 1(a)(6) shall be deleted, de-identified, or otherwise modified with respect to the purposes for which it was collected or processed and the sensitivity of the covered dataCovered data"covered data", information, including derived data, inferences, and unique persistent identifiers that identifies or is linked or reasonably linkable, alone or in combination with other information, to an individual or a device that identifies or is linked or reasonably linkable to an individual. However, the term "covered data" does not include de-identified data or publicly available information.Ch. 93N § 1(a)(6); and (5) implement reasonable training and safeguards within the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) and service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) to promote compliance with all privacy laws applicable to covered dataCovered data"covered data", information, including derived data, inferences, and unique persistent identifiers that identifies or is linked or reasonably linkable, alone or in combination with other information, to an individual or a device that identifies or is linked or reasonably linkable to an individual. However, the term "covered data" does not include de-identified data or publicly available information.Ch. 93N § 1(a)(6) the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) collects, processes, or transfers or covered dataCovered data"covered data", information, including derived data, inferences, and unique persistent identifiers that identifies or is linked or reasonably linkable, alone or in combination with other information, to an individual or a device that identifies or is linked or reasonably linkable to an individual. However, the term "covered data" does not include de-identified data or publicly available information.Ch. 93N § 1(a)(6) the service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) collects, processes, or transfers on behalf of the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) and mitigate privacy risks taking into account the role of the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) or service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) and the information available to it.
(b)(1)–(5) 6 The policies, practices, and procedures established by a covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) or service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) under subsection (a), shall correspond with, as applicable: (1) the size of the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) or the service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) and the nature, scope, and complexity of the activities engaged in by the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) or service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28)... (2) the sensitivity of the covered dataCovered data"covered data", information, including derived data, inferences, and unique persistent identifiers that identifies or is linked or reasonably linkable, alone or in combination with other information, to an individual or a device that identifies or is linked or reasonably linkable to an individual. However, the term "covered data" does not include de-identified data or publicly available information.Ch. 93N § 1(a)(6) collected, processed, or transferred by the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) or service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28); (3) the volume of covered dataCovered data"covered data", information, including derived data, inferences, and unique persistent identifiers that identifies or is linked or reasonably linkable, alone or in combination with other information, to an individual or a device that identifies or is linked or reasonably linkable to an individual. However, the term "covered data" does not include de-identified data or publicly available information.Ch. 93N § 1(a)(6) collected, processed, or transferred by the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) or service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28); (4) the number of individualsIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) and devices to which the covered dataCovered data"covered data", information, including derived data, inferences, and unique persistent identifiers that identifies or is linked or reasonably linkable, alone or in combination with other information, to an individual or a device that identifies or is linked or reasonably linkable to an individual. However, the term "covered data" does not include de-identified data or publicly available information.Ch. 93N § 1(a)(6) collected, processed, or transferred by the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) or service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) relates; and (5) the cost of implementing such policies, practices, and procedures in relation to the risks and nature of the covered dataCovered data"covered data", information, including derived data, inferences, and unique persistent identifiers that identifies or is linked or reasonably linkable, alone or in combination with other information, to an individual or a device that identifies or is linked or reasonably linkable to an individual. However, the term "covered data" does not include de-identified data or publicly available information.Ch. 93N § 1(a)(6).
Section 5 requires covered entities and service providers to establish, implement, and maintain reasonable privacy policies, practices, and procedures — a privacy-by-design obligation. These must address applicable law, minor-specific privacy risks, product lifecycle privacy risks, data retention evaluation, and employee training. The program must be scaled proportionally to the entity's size, data sensitivity, data volume, number of affected individuals, and implementation costs.
(a)–(c) 7 A covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) may not retaliate against an individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) for: (1) exercising any of the rights guaranteed by this chapter, or any regulations promulgated under this chapter; or (2) refusing to agree to collection or processing of covered dataCovered data"covered data", information, including derived data, inferences, and unique persistent identifiers that identifies or is linked or reasonably linkable, alone or in combination with other information, to an individual or a device that identifies or is linked or reasonably linkable to an individual. However, the term "covered data" does not include de-identified data or publicly available information.Ch. 93N § 1(a)(6) for a separate product or service, including denying goods or services, charging different prices or rates for goods or services, or providing a different level of quality of goods or services. (b) Nothing in subsection (a) shall be construed to: (1) prohibit the relation of the price of a service or the level of service provided to an individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) to the provision, by the individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14), of financial information that is necessarily collected and processed only for the purpose of initiating, rendering, billing for, or collecting payment for a service or product requested by the individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14); (2) prohibit a covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) from offering a different price, rate, level, quality or selection of goods or services to an individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14), including offering goods or services for no fee, if the offering is in connection with an individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14)'s voluntary participation in a bona fide loyalty, rewards, premium features, discount or club card program... (3)–(6)... (c) Notwithstanding the provisions in this section, no covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) may offer different types of pricing that are unjust, unreasonable, coercive, or usurious in nature.
Section 6 prohibits covered entities from retaliating against individuals for exercising rights under the chapter or for refusing data collection for unrelated products — including through price discrimination, service denial, or service degradation. The section carves out bona fide loyalty programs, financial incentives for market research, and situations where data collection is strictly necessary for the product. A blanket prohibition bars unjust, unreasonable, coercive, or usurious pricing regardless of the carve-outs.
(a)–(b) 8 A covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) or a service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) may not collect, process, or transfer covered dataCovered data"covered data", information, including derived data, inferences, and unique persistent identifiers that identifies or is linked or reasonably linkable, alone or in combination with other information, to an individual or a device that identifies or is linked or reasonably linkable to an individual. However, the term "covered data" does not include de-identified data or publicly available information.Ch. 93N § 1(a)(6) or publicly available data in a manner that discriminates in or otherwise makes unavailable the equal enjoyment of goods or services (i.e., has a disparate impact) on the basis of race, color, religion, national origin, sex, sexual orientation, gender identity, disability, genetic information, neural dataNeural data"neural data", means information that is generated by measuring the activity of an individual's central or peripheral nervous system, and that is not inferred from non-neural information.Ch. 93N § 1(a)(19), pregnancy or a condition related to said pregnancy including, but not limited to, lactation or the need to express breast milk for a nursing child, ancestry or status as a veteran, or any other basis protected by chapter 151B. (b) This subsection shall not apply to: (1) the collection, processing, or transfer of covered dataCovered data"covered data", information, including derived data, inferences, and unique persistent identifiers that identifies or is linked or reasonably linkable, alone or in combination with other information, to an individual or a device that identifies or is linked or reasonably linkable to an individual. However, the term "covered data" does not include de-identified data or publicly available information.Ch. 93N § 1(a)(6) for the purpose of: (i) covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7)'s or a service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28)'s self-testing to prevent or mitigate unlawful discrimination; or (ii) diversifying an applicant, participant, or customer pool; or (2) any private club or group not open to the public, as described in section 201(e) of the Civil Rights Act of 1964, 42 U.S.C. section 2000a(e).
(c) 8 Whenever the Attorney General obtains information that a covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) or service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) may have collected, processed, or transferred covered dataCovered data"covered data", information, including derived data, inferences, and unique persistent identifiers that identifies or is linked or reasonably linkable, alone or in combination with other information, to an individual or a device that identifies or is linked or reasonably linkable to an individual. However, the term "covered data" does not include de-identified data or publicly available information.Ch. 93N § 1(a)(6) in violation of subsection (a), the Attorney General shall initiate enforcement actions relating to such violation in accordance with section 12 of this chapter. (1) Not later than 3 years after the date of enactment of this chapter, and annually no later than December 31 of each year thereafter, the Attorney General shall submit to the joint committee on ways and means, the joint committee on racial equity, civil rights, and inclusion, and the joint committee on advanced information technology, the internet and cybersecurity a report that includes a summary of the enforcement actions taken under this subsection.
Section 7 prohibits covered entities and service providers from collecting, processing, or transferring covered data or publicly available data in a manner that discriminates in or makes unavailable the equal enjoyment of goods or services on the basis of protected characteristics — expressly including neural data as a protected basis. The section incorporates a disparate impact standard. Exceptions exist for self-testing to prevent discrimination and for diversifying applicant pools. The Attorney General must initiate enforcement upon receiving information of a violation and must submit annual enforcement reports to legislative committees beginning three years after enactment.
(a)–(c) 9 Each covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) or service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) shall make publicly available, in a clear and conspicuous location on its homepage, a reasonably understandable and not misleading privacy policy that provides a detailed and accurate representation of the data collection, processing, and transfer activities of the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) or service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28). (b) The privacy policy must be provided in a manner that is reasonably accessible to and usable by individualsIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) with disabilities... (c) The privacy policy must include, at a minimum: (1) The identity and the contact information of: (i) the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) or service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) to which the privacy policy applies... (ii) any other entity within the same corporate structure... (2) the categories of covered dataCovered data"covered data", information, including derived data, inferences, and unique persistent identifiers that identifies or is linked or reasonably linkable, alone or in combination with other information, to an individual or a device that identifies or is linked or reasonably linkable to an individual. However, the term "covered data" does not include de-identified data or publicly available information.Ch. 93N § 1(a)(6) the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) or service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) collects or processes; (3) the processing purposes for each category of covered dataCovered data"covered data", information, including derived data, inferences, and unique persistent identifiers that identifies or is linked or reasonably linkable, alone or in combination with other information, to an individual or a device that identifies or is linked or reasonably linkable to an individual. However, the term "covered data" does not include de-identified data or publicly available information.Ch. 93N § 1(a)(6)... (4) whether the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) or service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) transfers covered dataCovered data"covered data", information, including derived data, inferences, and unique persistent identifiers that identifies or is linked or reasonably linkable, alone or in combination with other information, to an individual or a device that identifies or is linked or reasonably linkable to an individual. However, the term "covered data" does not include de-identified data or publicly available information.Ch. 93N § 1(a)(6) and, if so, each category of service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) and third partyThird party"third party", any person or entity, including a covered entity, that (i) collects, processes, or transfers covered data and is not a consumer-facing business with which the individual linked or reasonably linkable to such covered data expects and intends to interact; and (ii) is not a service provider with respect to such data. This term does not include a person or entity that collects covered data from another entity if the two entities are related by common ownership or corporate control, but only if a reasonable consumer's reasonable expectation would be that such entities share information.Ch. 93N § 1(a)(31) to which the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) or service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) transfers covered dataCovered data"covered data", information, including derived data, inferences, and unique persistent identifiers that identifies or is linked or reasonably linkable, alone or in combination with other information, to an individual or a device that identifies or is linked or reasonably linkable to an individual. However, the term "covered data" does not include de-identified data or publicly available information.Ch. 93N § 1(a)(6)... (5) The length of time the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) or service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) intends to retain each category of covered dataCovered data"covered data", information, including derived data, inferences, and unique persistent identifiers that identifies or is linked or reasonably linkable, alone or in combination with other information, to an individual or a device that identifies or is linked or reasonably linkable to an individual. However, the term "covered data" does not include de-identified data or publicly available information.Ch. 93N § 1(a)(6)... (6) A prominent, clear, and reasonably understandable description of how an individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) can exercise the rights described in this chapter; (7) A general description of the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7)'s or service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28)'s data security practices; and (8) The effective date of the privacy policy.
(d)–(e) 9 If a covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) or service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) makes a material change to its privacy policy or practices, the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) or service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) shall notify each individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) affected by such material change before implementing the material change with respect to any prospectively collected covered dataCovered data"covered data", information, including derived data, inferences, and unique persistent identifiers that identifies or is linked or reasonably linkable, alone or in combination with other information, to an individual or a device that identifies or is linked or reasonably linkable to an individual. However, the term "covered data" does not include de-identified data or publicly available information.Ch. 93N § 1(a)(6) and provide a reasonable opportunity for each individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) to withdraw consentConsent"consent", a clear affirmative act signifying an individual's freely given, specific, informed, and unambiguous agreement to allow the processing of specific categories of personal information relating to the individual for a narrowly defined particular purpose after having been informed, in response to a specific request from a covered entity that meets the requirements of this chapter; provided, however, that "consent" may include a written statement, including a statement written by electronic means, or any other unambiguous affirmative action; and provided further, that the following shall not constitute "consent": (i) acceptance of a general or broad terms of use or similar document that contains descriptions of personal information processing along with other, unrelated information; (ii) hovering over, muting, pausing, or closing a given piece of content; or (iii) agreement obtained through dark patterns or a false, fictitious, fraudulent, or materially misleading statement or representation.Ch. 93N § 1(a)(4) to any further materially different collection, processing, or transfer of previously collected covered dataCovered data"covered data", information, including derived data, inferences, and unique persistent identifiers that identifies or is linked or reasonably linkable, alone or in combination with other information, to an individual or a device that identifies or is linked or reasonably linkable to an individual. However, the term "covered data" does not include de-identified data or publicly available information.Ch. 93N § 1(a)(6) under the changed policy. (e) A covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) or service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) shall take all reasonable electronic measures to provide direct notification regarding material changes to the privacy policy to each affected individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14)...
(g)–(j) 10 Each large data holderLarge data holder"large data holder", a covered entity or service provider that in the most recent calendar year: (i) had annual gross revenues of $200,000,000 or more; and (ii) collected, processed, or transferred the covered data of more than 2,000,000 individuals or devices that identify or are linked or reasonably linkable to one or more individuals, excluding covered data collected and processed solely for the purpose of initiating, rendering, billing for, finalizing, completing, or otherwise collecting payment for a requested product or service; or the sensitive covered data of more than 200,000 individuals or devices that identify or are linked or reasonably linkable to one or more individuals. The term "large data holder" does not include any instance in which the covered entity or service provider would qualify as a large data holder solely on the basis of collecting or processing personal email addresses, personal telephone numbers, or log-in information of an individual or device to allow the individual or device to log in to an account administered by the covered entity or service provider.Ch. 93N § 1(a)(16) shall retain copies of previous versions of its privacy policy for at least 10 years beginning after the date of enactment of this chapter and publish them on its website. Such large data holderLarge data holder"large data holder", a covered entity or service provider that in the most recent calendar year: (i) had annual gross revenues of $200,000,000 or more; and (ii) collected, processed, or transferred the covered data of more than 2,000,000 individuals or devices that identify or are linked or reasonably linkable to one or more individuals, excluding covered data collected and processed solely for the purpose of initiating, rendering, billing for, finalizing, completing, or otherwise collecting payment for a requested product or service; or the sensitive covered data of more than 200,000 individuals or devices that identify or are linked or reasonably linkable to one or more individuals. The term "large data holder" does not include any instance in which the covered entity or service provider would qualify as a large data holder solely on the basis of collecting or processing personal email addresses, personal telephone numbers, or log-in information of an individual or device to allow the individual or device to log in to an account administered by the covered entity or service provider.Ch. 93N § 1(a)(16) shall make publicly available, in a clear, conspicuous, and readily accessible manner, a log describing the date and nature of each material change to its privacy policy over the past 10 years... (h) In addition to the privacy policy required under subsection (a), a large data holderLarge data holder"large data holder", a covered entity or service provider that in the most recent calendar year: (i) had annual gross revenues of $200,000,000 or more; and (ii) collected, processed, or transferred the covered data of more than 2,000,000 individuals or devices that identify or are linked or reasonably linkable to one or more individuals, excluding covered data collected and processed solely for the purpose of initiating, rendering, billing for, finalizing, completing, or otherwise collecting payment for a requested product or service; or the sensitive covered data of more than 200,000 individuals or devices that identify or are linked or reasonably linkable to one or more individuals. The term "large data holder" does not include any instance in which the covered entity or service provider would qualify as a large data holder solely on the basis of collecting or processing personal email addresses, personal telephone numbers, or log-in information of an individual or device to allow the individual or device to log in to an account administered by the covered entity or service provider.Ch. 93N § 1(a)(16) that is a covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) shall provide a short form notice of no more than 500 words in length that includes the main features of their data practices. (i) Each covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) or service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) that collects, processes, or transfers biometric data shall provide a separate privacy policy detailing the collection, processing, and transfer of such biometric data... (j) Each covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) or service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) that collects, processes, or transfers specific precise geolocation information shall provide a separate privacy policy detailing the collection, processing, and transfer of such precise geolocation information...
Section 8 mandates that every covered entity and service provider publish a detailed, accessible, and not misleading privacy policy on its homepage. The policy must enumerate the entity's identity and contact information, data categories collected, processing purposes, third-party recipients, retention periods, individual rights descriptions, data security practices, and effective date. Material changes require advance notice and an opportunity to withdraw consent. Large data holders must maintain a 10-year archive of prior policies, a public change log, and provide a 500-word short-form notice. Separate privacy policies are required for biometric data and precise geolocation information.
(a)–(b) 11 A covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) or service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) shall provide an individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) with a clear and conspicuous, easy-to-execute means to withdraw consentConsent"consent", a clear affirmative act signifying an individual's freely given, specific, informed, and unambiguous agreement to allow the processing of specific categories of personal information relating to the individual for a narrowly defined particular purpose after having been informed, in response to a specific request from a covered entity that meets the requirements of this chapter; provided, however, that "consent" may include a written statement, including a statement written by electronic means, or any other unambiguous affirmative action; and provided further, that the following shall not constitute "consent": (i) acceptance of a general or broad terms of use or similar document that contains descriptions of personal information processing along with other, unrelated information; (ii) hovering over, muting, pausing, or closing a given piece of content; or (iii) agreement obtained through dark patterns or a false, fictitious, fraudulent, or materially misleading statement or representation.Ch. 93N § 1(a)(4). Those means shall be at least as easy to execute by an individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) as the means to provide consentConsent"consent", a clear affirmative act signifying an individual's freely given, specific, informed, and unambiguous agreement to allow the processing of specific categories of personal information relating to the individual for a narrowly defined particular purpose after having been informed, in response to a specific request from a covered entity that meets the requirements of this chapter; provided, however, that "consent" may include a written statement, including a statement written by electronic means, or any other unambiguous affirmative action; and provided further, that the following shall not constitute "consent": (i) acceptance of a general or broad terms of use or similar document that contains descriptions of personal information processing along with other, unrelated information; (ii) hovering over, muting, pausing, or closing a given piece of content; or (iii) agreement obtained through dark patterns or a false, fictitious, fraudulent, or materially misleading statement or representation.Ch. 93N § 1(a)(4) and shall, at a minimum, be accessible in the same or a substantially similar location as the privacy policies required by section 8. (b) A covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) or service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) shall provide an individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) with a clear and conspicuous, easy-to-execute means to opt out of covered dataCovered data"covered data", information, including derived data, inferences, and unique persistent identifiers that identifies or is linked or reasonably linkable, alone or in combination with other information, to an individual or a device that identifies or is linked or reasonably linkable to an individual. However, the term "covered data" does not include de-identified data or publicly available information.Ch. 93N § 1(a)(6) transfers. Those means shall be at least as easy to execute by an individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) as the means to provide consentConsent"consent", a clear affirmative act signifying an individual's freely given, specific, informed, and unambiguous agreement to allow the processing of specific categories of personal information relating to the individual for a narrowly defined particular purpose after having been informed, in response to a specific request from a covered entity that meets the requirements of this chapter; provided, however, that "consent" may include a written statement, including a statement written by electronic means, or any other unambiguous affirmative action; and provided further, that the following shall not constitute "consent": (i) acceptance of a general or broad terms of use or similar document that contains descriptions of personal information processing along with other, unrelated information; (ii) hovering over, muting, pausing, or closing a given piece of content; or (iii) agreement obtained through dark patterns or a false, fictitious, fraudulent, or materially misleading statement or representation.Ch. 93N § 1(a)(4) and shall, at a minimum, be accessible in the same or a substantially similar location as the privacy policies required by section 8.
(c)–(d) 12 Right to opt out of profilingProfiling"profiling", any form of automated processing performed on personal data to evaluate, analyze or predict personal aspects related to an identified or identifiable individual's economic situation, health, personal preferences, interests, reliability, behavior, location or movements.Ch. 93N § 1(a)(24). A covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) or service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) that engages in profilingProfiling"profiling", any form of automated processing performed on personal data to evaluate, analyze or predict personal aspects related to an identified or identifiable individual's economic situation, health, personal preferences, interests, reliability, behavior, location or movements.Ch. 93N § 1(a)(24) in furtherance of automated decisions that produce legal or similarly significant effects on an individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) shall: (1) provide such individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) with a clear and conspicuous means to opt out of such profilingProfiling"profiling", any form of automated processing performed on personal data to evaluate, analyze or predict personal aspects related to an identified or identifiable individual's economic situation, health, personal preferences, interests, reliability, behavior, location or movements.Ch. 93N § 1(a)(24); and (2) allow an individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) to object to such profilingProfiling"profiling", any form of automated processing performed on personal data to evaluate, analyze or predict personal aspects related to an identified or identifiable individual's economic situation, health, personal preferences, interests, reliability, behavior, location or movements.Ch. 93N § 1(a)(24) through an opt out mechanism, at a minimum, accessible in the same or a substantially similar location as the privacy policies required by section 9. (d) A covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) or service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) that receives an opt out notification pursuant to this section shall abide by such opt out designations in a commercially reasonable timeframe. Such covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) or service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) shall notify any other person that directed the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) or service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) to either serve, deliver, or otherwise process targeted advertisements or to engage in profilingProfiling"profiling", any form of automated processing performed on personal data to evaluate, analyze or predict personal aspects related to an identified or identifiable individual's economic situation, health, personal preferences, interests, reliability, behavior, location or movements.Ch. 93N § 1(a)(24) in furtherance of automated decisions of the individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14)'s opt out decision within a commercially reasonable timeframe.
(e)–(i) 11 A covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) or service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) may not condition, effectively condition, attempt to condition, or attempt to effectively condition the exercise of any individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) right under this section through: (1) the use of any false, fictitious, fraudulent, or materially misleading statement or representation; or (2) the use of a dark pattern or deceptive designDark pattern or deceptive design"dark pattern or deceptive design", a user interface that is designed, modified, or manipulated with the purpose or substantial effect of obscuring, subverting, or impairing a reasonable individual's autonomy, decision-making, or choice, including, but not limited to, any practice the Federal Trade Commission refers to as a "dark pattern."Ch. 93N § 1(a)(9). (f) A covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) shall notify third parties who had access to an individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14)'s covered dataCovered data"covered data", information, including derived data, inferences, and unique persistent identifiers that identifies or is linked or reasonably linkable, alone or in combination with other information, to an individual or a device that identifies or is linked or reasonably linkable to an individual. However, the term "covered data" does not include de-identified data or publicly available information.Ch. 93N § 1(a)(6) when the individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) exercises any of the rights established in this section. The third partyThird party"third party", any person or entity, including a covered entity, that (i) collects, processes, or transfers covered data and is not a consumer-facing business with which the individual linked or reasonably linkable to such covered data expects and intends to interact; and (ii) is not a service provider with respect to such data. This term does not include a person or entity that collects covered data from another entity if the two entities are related by common ownership or corporate control, but only if a reasonable consumer's reasonable expectation would be that such entities share information.Ch. 93N § 1(a)(31) shall comply with the request to opt out of sale or data transfer forwarded to them from a covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7)... (g) A covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) that communicates an individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14)'s opt out request to a third partyThird party"third party", any person or entity, including a covered entity, that (i) collects, processes, or transfers covered data and is not a consumer-facing business with which the individual linked or reasonably linkable to such covered data expects and intends to interact; and (ii) is not a service provider with respect to such data. This term does not include a person or entity that collects covered data from another entity if the two entities are related by common ownership or corporate control, but only if a reasonable consumer's reasonable expectation would be that such entities share information.Ch. 93N § 1(a)(31) or service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) pursuant to this section shall not be liable under this chapter if the third partyThird party"third party", any person or entity, including a covered entity, that (i) collects, processes, or transfers covered data and is not a consumer-facing business with which the individual linked or reasonably linkable to such covered data expects and intends to interact; and (ii) is not a service provider with respect to such data. This term does not include a person or entity that collects covered data from another entity if the two entities are related by common ownership or corporate control, but only if a reasonable consumer's reasonable expectation would be that such entities share information.Ch. 93N § 1(a)(31) or service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) receiving the opt-out request violates the restrictions set forth in this chapter; provided, however, that at the time of communicating the opt-out request, the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) does not know or should not reasonably know that the third partyThird party"third party", any person or entity, including a covered entity, that (i) collects, processes, or transfers covered data and is not a consumer-facing business with which the individual linked or reasonably linkable to such covered data expects and intends to interact; and (ii) is not a service provider with respect to such data. This term does not include a person or entity that collects covered data from another entity if the two entities are related by common ownership or corporate control, but only if a reasonable consumer's reasonable expectation would be that such entities share information.Ch. 93N § 1(a)(31) or service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) intends to commit such a violation. (h) If an individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) decides to opt out of the processing of the individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14)'s covered dataCovered data"covered data", information, including derived data, inferences, and unique persistent identifiers that identifies or is linked or reasonably linkable, alone or in combination with other information, to an individual or a device that identifies or is linked or reasonably linkable to an individual. However, the term "covered data" does not include de-identified data or publicly available information.Ch. 93N § 1(a)(6) for the purposes specified in subsections (b), (c), or (d) and such decision conflicts with the individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14)'s existing, voluntary participation in a covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7)'s bona fide loyalty, rewards, premium features, discounts or club card program, the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) shall comply with the individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14)'s opt out preference signal but may notify the individual of the conflict... (i) A covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) or service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) shall not require an individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) to create an account for the purposes of exercising any right under this chapter.
Section 9 establishes advanced opt-out rights beyond the basic data subject rights in Section 3. Individuals must be provided with clear, easy-to-execute means to withdraw consent, opt out of data transfers, and opt out of profiling in furtherance of automated decisions that produce legal or similarly significant effects. Covered entities must honor opt-out designations in a commercially reasonable timeframe and propagate them to third parties. The section prohibits conditioning these rights through misrepresentation or dark patterns, and requires covered entities not to require account creation for rights exercise.
(a)(1)–(8) 13 A service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28): (1) shall adhere to the instructions of a covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) and only collect, process, and transfer service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) data to the extent necessary and proportionate to provide a service requested by the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7), as set out in the contract required by subsection (b)... (2) may not collect, process, or transfer service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) data if the service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) has actual knowledgeKnowledge"knowledge", (i) with respect to a covered entity that is a covered high-impact social media company, the entity knew or should have known the individual was a minor; (ii) with respect to a covered entity or service provider that is a large data holder, and otherwise is not a covered high-impact social media company, that the covered entity knew or acted in willful disregard of the fact that the individual was a minor; and (iii) with respect to a covered entity or service provider that does not meet the requirements of clause (i) or (ii), actual knowledge.Ch. 93N § 1(a)(15) that a covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) violated this chapter with respect to such data; (3) shall assist a covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) in responding to a request made by an individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) under this chapter... (4) may engage another service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) for purposes of processing service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) data on behalf of a covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) only after providing that covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) with notice and pursuant to a written contract... (5) shall, upon the reasonable request of the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7), make available to the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) information necessary to demonstrate the compliance of the service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28)... (6) shall, at the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7)'s direction, delete or return all covered dataCovered data"covered data", information, including derived data, inferences, and unique persistent identifiers that identifies or is linked or reasonably linkable, alone or in combination with other information, to an individual or a device that identifies or is linked or reasonably linkable to an individual. However, the term "covered data" does not include de-identified data or publicly available information.Ch. 93N § 1(a)(6) to the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) as requested at the end of the provision of services... (7) shall develop, implement, and maintain reasonable administrative, technical, and physical safeguards that are designed to protect the security and confidentiality of covered dataCovered data"covered data", information, including derived data, inferences, and unique persistent identifiers that identifies or is linked or reasonably linkable, alone or in combination with other information, to an individual or a device that identifies or is linked or reasonably linkable to an individual. However, the term "covered data" does not include de-identified data or publicly available information.Ch. 93N § 1(a)(6)... (8) shall allow and cooperate with reasonable assessments by the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) or the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7)'s designated assessor...
(b)(1)–(4) 13 A person or entity may only act as a service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) pursuant to a written contract between the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) and the service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28)... if the contract: (1) sets forth the data processing procedures of the service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) with respect to collection, processing, or transfer performed on behalf of the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) or service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28); (2) clearly sets forth: (i) instructions for collecting, processing, or transferring data; (ii) the nature and purpose of collecting, processing, or transferring; (iii) the type of data subject to collecting, processing, or transferring; (iv) the duration of processing; and (v) the rights and obligations of both parties, including a method by which the service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) shall notify the covered entity of material changes to its privacy practices; (3) does not relieve a covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) or a service provider of any requirement or liability imposed on such covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) or service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) under this chapter; and (4) prohibits: (i) collecting, processing, or transferring covered dataCovered data"covered data", information, including derived data, inferences, and unique persistent identifiers that identifies or is linked or reasonably linkable, alone or in combination with other information, to an individual or a device that identifies or is linked or reasonably linkable to an individual. However, the term "covered data" does not include de-identified data or publicly available information.Ch. 93N § 1(a)(6) in contravention to subsection (a); and (ii) combining service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) data with covered dataCovered data"covered data", information, including derived data, inferences, and unique persistent identifiers that identifies or is linked or reasonably linkable, alone or in combination with other information, to an individual or a device that identifies or is linked or reasonably linkable to an individual. However, the term "covered data" does not include de-identified data or publicly available information.Ch. 93N § 1(a)(6) which the service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) receives from or on behalf of another person or persons or collects from the interaction of the service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) with an individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14)...
(c)–(f) 13 Each service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) shall retain copies of previous contracts entered into in compliance with this subsection with each covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) to which it provides requested products or services. (d) The classification of a person or entity as a covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) or as a service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) and the relationship between covered entities and service providersService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) are regulated by the following provisions: (1) Determining whether a person is acting as a covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) or service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) with respect to a specific processing of covered dataCovered data"covered data", information, including derived data, inferences, and unique persistent identifiers that identifies or is linked or reasonably linkable, alone or in combination with other information, to an individual or a device that identifies or is linked or reasonably linkable to an individual. However, the term "covered data" does not include de-identified data or publicly available information.Ch. 93N § 1(a)(6) is a fact-based determination... (2) A person or entity that is not limited in its processing of covered dataCovered data"covered data", information, including derived data, inferences, and unique persistent identifiers that identifies or is linked or reasonably linkable, alone or in combination with other information, to an individual or a device that identifies or is linked or reasonably linkable to an individual. However, the term "covered data" does not include de-identified data or publicly available information.Ch. 93N § 1(a)(6) pursuant to the instructions of a covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7), or that fails to adhere to such instructions, is a covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) and not a service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28)... (3) A covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) that transfers covered dataCovered data"covered data", information, including derived data, inferences, and unique persistent identifiers that identifies or is linked or reasonably linkable, alone or in combination with other information, to an individual or a device that identifies or is linked or reasonably linkable to an individual. However, the term "covered data" does not include de-identified data or publicly available information.Ch. 93N § 1(a)(6) to a service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28)... in compliance with the requirements of this chapter, is not liable for a violation of this chapter by the service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28)... (4) A covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) or service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) that receives covered dataCovered data"covered data", information, including derived data, inferences, and unique persistent identifiers that identifies or is linked or reasonably linkable, alone or in combination with other information, to an individual or a device that identifies or is linked or reasonably linkable to an individual. However, the term "covered data" does not include de-identified data or publicly available information.Ch. 93N § 1(a)(6) in compliance with the requirements of this chapter is not in violation of this chapter as a result of a violation by a covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) or service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) from which such data was received. (e) A third partyThird party"third party", any person or entity, including a covered entity, that (i) collects, processes, or transfers covered data and is not a consumer-facing business with which the individual linked or reasonably linkable to such covered data expects and intends to interact; and (ii) is not a service provider with respect to such data. This term does not include a person or entity that collects covered data from another entity if the two entities are related by common ownership or corporate control, but only if a reasonable consumer's reasonable expectation would be that such entities share information.Ch. 93N § 1(a)(31): (1) shall not process third partyThird party"third party", any person or entity, including a covered entity, that (i) collects, processes, or transfers covered data and is not a consumer-facing business with which the individual linked or reasonably linkable to such covered data expects and intends to interact; and (ii) is not a service provider with respect to such data. This term does not include a person or entity that collects covered data from another entity if the two entities are related by common ownership or corporate control, but only if a reasonable consumer's reasonable expectation would be that such entities share information.Ch. 93N § 1(a)(31) data for a processing purpose other than the processing purpose for which (i) the individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) gave consentConsent"consent", a clear affirmative act signifying an individual's freely given, specific, informed, and unambiguous agreement to allow the processing of specific categories of personal information relating to the individual for a narrowly defined particular purpose after having been informed, in response to a specific request from a covered entity that meets the requirements of this chapter; provided, however, that "consent" may include a written statement, including a statement written by electronic means, or any other unambiguous affirmative action; and provided further, that the following shall not constitute "consent": (i) acceptance of a general or broad terms of use or similar document that contains descriptions of personal information processing along with other, unrelated information; (ii) hovering over, muting, pausing, or closing a given piece of content; or (iii) agreement obtained through dark patterns or a false, fictitious, fraudulent, or materially misleading statement or representation.Ch. 93N § 1(a)(4)... or (ii) the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) made a disclosure pursuant to their privacy policy... (f) Solely for the purposes of this section, the requirements for service providersService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) to contract with, assist, and follow the instructions of covered entities shall be read to include requirements to contract with, assist, and follow the instructions of a government entity if the service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) is providing a service to a government entity.
Section 10 governs the relationship between covered entities and service providers. Service providers must adhere to covered entity instructions, assist with individual rights requests, maintain data security safeguards, and allow compliance assessments. All service provider relationships must be governed by written contracts specifying processing procedures, data types, processing purposes, duration, and mutual obligations. The section establishes fact-based determination of covered entity vs. service provider status, liability protections for good-faith data transfers, and restrictions on third-party data use.
(a)–(k) A violation of this chapter constitutes an injury to that individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) and shall be deemed an unfair or deceptive act or practice in the conduct of trade or commerce under chapter 93A, provided that if the court finds for any petitioner, subject to section 9, paragraph (3) ofsuch chapter, recovery under such chapter shall be in the amount of actual damages or $5,000, whichever is higher. (b) Private right of action. Any individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) alleging a violation of this chapter by a covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7), service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28), or third partyThird party"third party", any person or entity, including a covered entity, that (i) collects, processes, or transfers covered data and is not a consumer-facing business with which the individual linked or reasonably linkable to such covered data expects and intends to interact; and (ii) is not a service provider with respect to such data. This term does not include a person or entity that collects covered data from another entity if the two entities are related by common ownership or corporate control, but only if a reasonable consumer's reasonable expectation would be that such entities share information.Ch. 93N § 1(a)(31) that is a large data holderLarge data holder"large data holder", a covered entity or service provider that in the most recent calendar year: (i) had annual gross revenues of $200,000,000 or more; and (ii) collected, processed, or transferred the covered data of more than 2,000,000 individuals or devices that identify or are linked or reasonably linkable to one or more individuals, excluding covered data collected and processed solely for the purpose of initiating, rendering, billing for, finalizing, completing, or otherwise collecting payment for a requested product or service; or the sensitive covered data of more than 200,000 individuals or devices that identify or are linked or reasonably linkable to one or more individuals. The term "large data holder" does not include any instance in which the covered entity or service provider would qualify as a large data holder solely on the basis of collecting or processing personal email addresses, personal telephone numbers, or log-in information of an individual or device to allow the individual or device to log in to an account administered by the covered entity or service provider.Ch. 93N § 1(a)(16) may bring a civil action in the superior court or any court of competent jurisdiction. (c) An individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) protected by this chapter may not be required, as a condition of service or otherwise, to file an administrative complaint with the attorney general or to accept mandatory arbitration of a claim under this chapter. (d) The civil action shall be directed to the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7), service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28), and third-parties alleged to have committed the violation. (e) In a civil action in which the plaintiff prevails, the court may award: (1) liquidated damages of not less than 0.15% of the annual global revenue of the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) or $15,000 per violation, whichever is greater; (2) punitive damages; and (3) any other relief, including but not limited to an injunction, that the court deems to be appropriate. (f) In addition to any relief awarded pursuant to the previous paragraph, the court shall award reasonable attorney's fees and costs to any prevailing plaintiff. (g) The Attorney General may bring an action pursuant to section 4 of chapter 93A against a covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7), service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28), or third partyThird party"third party", any person or entity, including a covered entity, that (i) collects, processes, or transfers covered data and is not a consumer-facing business with which the individual linked or reasonably linkable to such covered data expects and intends to interact; and (ii) is not a service provider with respect to such data. This term does not include a person or entity that collects covered data from another entity if the two entities are related by common ownership or corporate control, but only if a reasonable consumer's reasonable expectation would be that such entities share information.Ch. 93N § 1(a)(31) to remedy violations of this chapter and for other relief, including but not limited to an injunction, that may be appropriate, subject to the following: (1) If the court finds that the defendant has employed any method, act, or practice which they knew or should have known to be in violation of this chapter, the court may require the defendant to pay to the commonwealth a civil penalty of: (i) not less than 0.15% of the annual global revenue or $15,000, whichever is greater, per violation; and (ii) not more than 4% of the annual global revenue of the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7), service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28), or third-party or $20,000,000, whichever is greater, per action if such action includes multiple violations to multiple individualsIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14); (2) If the court finds that a defendant has engaged in flagrant, willful and repeat violations of this chapter, the court may issue an order to suspend or prohibit a covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7), service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28), or third partyThird party"third party", any person or entity, including a covered entity, that (i) collects, processes, or transfers covered data and is not a consumer-facing business with which the individual linked or reasonably linkable to such covered data expects and intends to interact; and (ii) is not a service provider with respect to such data. This term does not include a person or entity that collects covered data from another entity if the two entities are related by common ownership or corporate control, but only if a reasonable consumer's reasonable expectation would be that such entities share information.Ch. 93N § 1(a)(31) from operating in the commonwealth or collecting, processing, and transferring covered dataCovered data"covered data", information, including derived data, inferences, and unique persistent identifiers that identifies or is linked or reasonably linkable, alone or in combination with other information, to an individual or a device that identifies or is linked or reasonably linkable to an individual. However, the term "covered data" does not include de-identified data or publicly available information.Ch. 93N § 1(a)(6) and any other relief, including but not limited to an injunction, that the court deems to be appropriate. (3) In addition to any penalty or relief awarded under this subsection, a defendant violating this chapter shall also be liable to the commonwealth for the reasonable costs of investigation and litigation of such violation, including reasonable attorneys' fees and reasonable expert fees. (h) When calculating awards and civil penalties in all the actions in this section, the court shall consider: (1) the number of affected individualsIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14); (2) the severity of the violation or noncompliance; (3) the risks caused by the violation or noncompliance; (4) whether the violation or noncompliance was part of a pattern of noncompliance and violations and not an isolated instance; (5) whether the violation or noncompliance was willful and not the result of error; (6) the precautions taken by the defendant to prevent a violation; (7) the number of administrative actions, lawsuits, settlements, and consentConsent"consent", a clear affirmative act signifying an individual's freely given, specific, informed, and unambiguous agreement to allow the processing of specific categories of personal information relating to the individual for a narrowly defined particular purpose after having been informed, in response to a specific request from a covered entity that meets the requirements of this chapter; provided, however, that "consent" may include a written statement, including a statement written by electronic means, or any other unambiguous affirmative action; and provided further, that the following shall not constitute "consent": (i) acceptance of a general or broad terms of use or similar document that contains descriptions of personal information processing along with other, unrelated information; (ii) hovering over, muting, pausing, or closing a given piece of content; or (iii) agreement obtained through dark patterns or a false, fictitious, fraudulent, or materially misleading statement or representation.Ch. 93N § 1(a)(4)-decrees under this chapter involving the defendant; (8) the number of administrative actions, lawsuits, settlements, and consentConsent"consent", a clear affirmative act signifying an individual's freely given, specific, informed, and unambiguous agreement to allow the processing of specific categories of personal information relating to the individual for a narrowly defined particular purpose after having been informed, in response to a specific request from a covered entity that meets the requirements of this chapter; provided, however, that "consent" may include a written statement, including a statement written by electronic means, or any other unambiguous affirmative action; and provided further, that the following shall not constitute "consent": (i) acceptance of a general or broad terms of use or similar document that contains descriptions of personal information processing along with other, unrelated information; (ii) hovering over, muting, pausing, or closing a given piece of content; or (iii) agreement obtained through dark patterns or a false, fictitious, fraudulent, or materially misleading statement or representation.Ch. 93N § 1(a)(4)-decrees involving the defendant in other states and at the federal level in issues involving information privacy; and (9) the international record of the defendant when it comes to information privacy issues. (i) It is a violation of this chapter for a covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) or anyone else acting on behalf of a covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) to retaliate against an individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) who makes a good-faith complaint that there has been a failure to comply with any part of this chapter. (1) An injured individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) by a violation of the previous paragraph may bring a civil action for monetary damages and injunctive relief in any court of competent jurisdiction. (j) Any provision of a contract or agreement of any kind, including a covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7)'s terms of service or a privacy policy, including the short-form privacy notice required under section 8 subsection (h) that purports to waive or limit in any way an individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14)'s rights under this chapter, including but not limited to any right to a remedy or means of enforcement shall be deemed contrary to public policy and shall be void and unenforceable. (k) No private or government action brought pursuant to this chapter shall preclude any other action under this chapter.
Section 11 establishes the enforcement framework. Violations are deemed unfair or deceptive acts under Chapter 93A with a statutory floor of $5,000 or actual damages (whichever is higher). A private right of action exists against large data holders, with liquidated damages of at least 0.15% of annual global revenue or $15,000 per violation (whichever is greater), plus punitive damages, injunctive relief, and mandatory attorney's fees. The Attorney General may bring actions with civil penalties up to 4% of annual global revenue or $20 million per multi-violation action. Courts may suspend or prohibit entities from operating in Massachusetts for flagrant, willful, repeat violations. Contractual waivers of rights under the chapter are void. Mandatory arbitration clauses and requirements to file administrative complaints may not be imposed.
(a)(1)–(5), (b) This chapter shall not apply to only the following specific types of information: (1) personal information captured from a patient by a health care provider or health care facility or biometric information collected, processed, used, or stored exclusively for medical education or research, public health or epidemiological purposes, health care treatment, insurance, payment, or operations under the federal Health Insurance Portability and Accountability Act of 1996, or to X-ray, roentgen process, computed tomography, MRI, PET scan, mammography, or other image or film of the human anatomy used exclusively to diagnose, prognose, or treat an illness or other medical condition or to further validate scientific testing or screening; (2) nonpublic personal information that is processed by a financial institution subject to, and in compliance with, the Gramm-Leach-Bliley Act, 15 U.S.C. 6801 et seq., as amended from time to time; (3) personal information regulated by the federal Family Educational Rights and Privacy Act, 20 U.S.C. 1232g et seq., as amended from time to time; (4) individualsIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) sharing their personal contact information such as email addresses with other individualsIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) in the workplace, or other social, political, or similar settings where the purpose of the information is to facilitate communication among such individualsIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14), provided that this chapter shall cover any processing of such contact information beyond interpersonal communication; or (5) covered entities' publication of entity-based member or employee contact information where such publication is intended to allow members of the public to contact such member or employee in the ordinary course of the entity's operations. (b) For the purpose of this section, the burden of proving that information is exempt from the provisions of this chapter shall be upon the party claiming the exemption.
Section 12 carves out specific categories of information from the chapter's coverage: HIPAA-covered patient information and medical imaging, Gramm-Leach-Bliley-regulated financial information, FERPA-regulated educational records, personal contact information shared for interpersonal communication, and entity-published employee contact information. The burden of proving an exemption falls on the party claiming it.
(a)–(c) The Attorney General shall adopt rules and regulations for the implementation, administration, and enforcement of this chapter and may from time to time amend or repeal said regulations. The rules and regulations shall include but are not limited to: (1) establishing or adopting baseline technical requirements that determine if a given dataset has been or can be considered sufficiently de-identified; (2) establishing reasonable policies, practices, and procedures that satisfy the requirements set forward in Section 5; (3) establishing a nonexclusive list of practices that constitute deceptive designs or dark patterns or otherwise violate the requirements set forward in Section 4. (b) The Attorney General may: (1) gather facts and information applicable to the Attorney General's obligation to enforce this chapter and ensure its compliance, consistent with the provisions of section 4 of chapter 93A; (2) conduct investigations for possible violations of this chapter; and (3) refer cases for civil enforcement or criminal prosecution to the appropriate federal, state, or local authorities. (c) The Attorney General shall, within one year after the effective date of chapter, create an official internet website that outlines the provisions of this chapter and provides individualsIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) with a form or other mechanism to report violations of this chapter to the Office of the Attorney General. The Attorney General shall update the website at least annually. The website shall include statistics on the Attorney General's enforcement actions undertaken under this chapter, broken down by fiscal year, including but not limited to: (1) number of complaints received; (2) number of open investigations; (3) number of closed investigations; and (4) a summary of case dispositions in which a violation of this chapter occurred.
Section 13 directs the Attorney General to adopt implementing regulations covering de-identification technical standards, privacy-by-design policies and procedures, and dark pattern definitions. The Attorney General is also authorized to investigate violations, refer cases for enforcement, and must create a public website within one year of enactment for violation reporting and enforcement statistics.
(a)–(e) 14 An individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) may designate another person to serve as the individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14)'s authorized agent to exercise the individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14)'s rights under section 3, to withdraw consentConsent"consent", a clear affirmative act signifying an individual's freely given, specific, informed, and unambiguous agreement to allow the processing of specific categories of personal information relating to the individual for a narrowly defined particular purpose after having been informed, in response to a specific request from a covered entity that meets the requirements of this chapter; provided, however, that "consent" may include a written statement, including a statement written by electronic means, or any other unambiguous affirmative action; and provided further, that the following shall not constitute "consent": (i) acceptance of a general or broad terms of use or similar document that contains descriptions of personal information processing along with other, unrelated information; (ii) hovering over, muting, pausing, or closing a given piece of content; or (iii) agreement obtained through dark patterns or a false, fictitious, fraudulent, or materially misleading statement or representation.Ch. 93N § 1(a)(4) under section 9, or opt out of the processing of such individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14)'s covered dataCovered data"covered data", information, including derived data, inferences, and unique persistent identifiers that identifies or is linked or reasonably linkable, alone or in combination with other information, to an individual or a device that identifies or is linked or reasonably linkable to an individual. However, the term "covered data" does not include de-identified data or publicly available information.Ch. 93N § 1(a)(6) for one or more of the purposes specified in section 9. (b) An individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) may designate an authorized agent as provided in subsection (a) by technological means, including, but not limited to, an Internet link or a browser setting, browser extension or global device setting that indicates the individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14)'s intent to opt out processing for one or more of the purposes specified in section 9. (c) A covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) or service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) shall comply with a request received from an authorized agent if the covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) or service providerService provider"service provider", a person or entity that: (i) collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a government agency; and (ii) receives covered data from or on behalf of a covered entity or a government agency. A service provider that receives service provider data from another service provider as permitted under this chapter shall be treated as a service provider under this chapter with respect to such data.Ch. 93N § 1(a)(28) is able to verify the identity of the individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) and the authorized agent's authority to act on such individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14)'s behalf by the same means and subject to the same restrictions as a covered entityCovered entity"covered entity", any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data. The term "covered entity" does not include: (i) government agencies or service providers to government agencies that exclusively and solely process information provided by government entities;Ch. 93N § 1(a)(7) under section 3(g). (d) In the case of covered dataCovered data"covered data", information, including derived data, inferences, and unique persistent identifiers that identifies or is linked or reasonably linkable, alone or in combination with other information, to an individual or a device that identifies or is linked or reasonably linkable to an individual. However, the term "covered data" does not include de-identified data or publicly available information.Ch. 93N § 1(a)(6) concerning an individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) known to be a child as defined by the Children's Online Privacy Protection Act, 15 U.S.C. 6501, the parent or legal guardian of such child may exercise the rights provided under this chapter on the child's behalf. (e) In the case of covered dataCovered data"covered data", information, including derived data, inferences, and unique persistent identifiers that identifies or is linked or reasonably linkable, alone or in combination with other information, to an individual or a device that identifies or is linked or reasonably linkable to an individual. However, the term "covered data" does not include de-identified data or publicly available information.Ch. 93N § 1(a)(6) concerning an individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) subject to a guardianship, conservatorship or other protective arrangement, the guardian or the conservator of the individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14) may exercise the rights provided under this chapter on the individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14)'s behalf.
Section 14 permits individuals to designate authorized agents — including by technological means such as browser settings or extensions — to exercise data subject rights and opt-out rights on their behalf. Covered entities must honor authorized agent requests subject to identity verification. Parents or legal guardians may exercise rights on behalf of children (as defined by COPPA), and guardians or conservators may exercise rights on behalf of individuals under protective arrangements.
(a)–(b) Should any provision of this chapter or part hereof be held under any circumstances in any court of competent jurisdiction to be invalid or unenforceable, such invalidity or unenforceability shall not affect the validity or enforceability of any other provision of this or other parts of this chapter. (b) Nothing in this chapter shall diminish any individualIndividual"individual", a natural person who is a Massachusetts resident or is present in Massachusetts.Ch. 93N § 1(a)(14)'s rights or obligations under chapters 66A, 93A, 93H, or under sections 1B or 3B of chapter 214.
Section 15 is a standard severability clause ensuring that invalidation of any provision does not affect the remainder of the chapter, and a savings clause preserving individual rights under existing Massachusetts privacy and consumer protection statutes (Chapters 66A, 93A, 93H, and sections 1B and 3B of Chapter 214).
This Act shall take effect 1 year after enactment.
The act takes effect one year after enactment, providing a compliance runway for covered entities and service providers.