WHAT THIS BILL REGULATES · 4 REQUIREMENT TYPES
How Is This Bill Enforced
Verbatim statutory text on the left; plain-language analysis and a per-section checklist on the right. Numbered markers cross-link to the matching checklist row.
As used in this chapter, unless the context otherwise requires: [all definitions in Section 1]
Section 1 establishes the definitional framework for the entire chapter. Key defined terms include Controller, Processor, Large data holder, Consumer, Personal data, Sensitive data, Affirmative Consent, Targeted advertising, Profiling, and Dark pattern. The definitions are broad — personal data encompasses derived data and unique identifiers, and sensitive data includes neural data, consumer health and wellness data, and minor data. The affirmative consent definition is unusually detailed, requiring stand-alone disclosures, language parity, and equal prominence for the option to refuse.
The provisions of this chapter apply to persons that conduct business in this state or persons that produce products or services that are targeted to residents of this state and that during the preceding calendar year: (a) Collected or processed the personal data of not less than 100,000 consumersConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1, excluding personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 controlled or processed solely for the purpose of completing a payment transaction, so long as all personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 collected or processed for such purpose was deleted or de-identified within 90 days, except when necessary to investigate fraud or as consistent with a business's return policy; (b) derived gross revenue from the sale of personal dataSale of personal data"Sale of personal data" means the exchange of personal data for monetary or other valuable consideration by the controller to a third party.Ch. 93M § 1; or (c) collected or processed sensitive dataSensitive data"Sensitive data" means personal data that includes: (i) data revealing a consumer's (A) racial or ethnic origin, color, national origin or citizenship or immigration status; (B) religious beliefs; (C) mental or physical health condition, diagnosis, disability or treatment, including, but not limited to, gender-affirming health data, reproductive or sexual health data or legally-protected health care data; (D) sex life, sexual orientation, status as transgender or non-binary; (E) union membership; (F) status as a victim of a crime; or (G) status as a military servicemember or veteran; (ii) consumer health and wellness data; (iii) genetic, neural, or biometric data; (iv) personal data of a consumer that a controller knows, or willfully disregards, is a minor; (v) precise geolocation data; (vi) a government-issued identifier, including a Social Security number, passport number or driver's license number, that is not required by law to be displayed in public; or (vii) account names, passwords, usernames, access codes, security questions or answers, or other credentials and information used to log in to an account or device.Ch. 93M § 1.
Section 2 defines the applicability thresholds for the chapter. The law applies to persons conducting business in Massachusetts or targeting Massachusetts residents that, in the preceding calendar year, collected or processed personal data of at least 100,000 consumers (excluding payment-only data deleted within 90 days), derived gross revenue from data sales, or collected or processed sensitive data. The sensitive data trigger is notably uncapped — any entity that collects or processes any sensitive data is covered regardless of volume or revenue.
(a)–(c) The provisions of this chapter, except for the provisions of paragraph (4) of subsection (a) of section 6, do not apply to: (1) any Federal, State, Tribal, territorial, or local government entity such as a body, authority, board, bureau, commission, district or agency of the Commonwealth or of any political subdivision of the Commonwealth; (2) a nonprofit organization established to detect and prevent fraudulent acts in connection with insurance that is operating solely for that purpose; (3) a national securities association registered pursuant to section 15A of the Securities Exchange Act of 1934 and the rules and implementing regulations promulgated thereunder; (4) a registered futures association designated pursuant to section 17 of the Commodity Exchange Act and the rules and implementing regulations promulgated thereunder; (5) a bank, credit union or any affiliate or subsidiary thereof that: (A) is only and directly engaged in financial activities as described in 12 USC 1843(k); (B) is regulated and examined by the division of banks or an applicable federal bank regulatory agency; and (C) has established a program to comply with all applicable requirements established by the commissioner of banks or the applicable federal bank regulatory agency concerning personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1; or (6) an agent, broker-dealer, investment adviser or investment adviser representative, as defined in section 401 of chapter 110A, who is regulated by the secretary of the commonwealth or the United States Securities and Exchange Commission. (b) The following information and data is exempt from the provisions of this chapter: [paragraphs (1)–(15) listing HIPAA data, GLBA data, FCRA data, FERPA data, employee data, etc.] (c) ControllersController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 and processorsProcessor"Processor" means a person who collects, processes, or transfers personal data on behalf of, and at the direction of, a controller or another processor, or a Federal, State, Tribal, or local government entity.Ch. 93M § 1 that comply with the verifiable parental consent requirements of COPPA shall be deemed compliant with any obligation to obtain parental consent pursuant to this chapter.
Section 3 exempts certain entities and data types from the chapter's coverage. Government entities, certain financial institutions, insurance fraud nonprofits, and registered securities associations are exempt at the entity level — except that the prohibition on sale of precise geolocation data applies to all entities. Extensive data-level exemptions track federal statutes including HIPAA, GLBA, FCRA, FERPA, and the Farm Credit Act. Employee and contractor data in the employment context is also exempt. COPPA-compliant verifiable parental consent is deemed sufficient under this chapter.
(a)(1)–(5) 1 A consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 shall have the right to: (1) Confirm whether or not a controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 is collecting or processing the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1's personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 and access such personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1, including, but not limited to, any inferences about the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 derived from such personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1; (2) obtain from a controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 a list of specific third parties, other than natural persons, to which the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 has transferred either (i) the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1's personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1; or (ii) any personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1; (3) correct inaccuracies in the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1's personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1, taking into account the nature of the personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 and the purposes of the processing of the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1's personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1, and instruct a controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 or processorProcessor"Processor" means a person who collects, processes, or transfers personal data on behalf of, and at the direction of, a controller or another processor, or a Federal, State, Tribal, or local government entity.Ch. 93M § 1 to make reasonable efforts to notify all third parties or processorsProcessor"Processor" means a person who collects, processes, or transfers personal data on behalf of, and at the direction of, a controller or another processor, or a Federal, State, Tribal, or local government entity.Ch. 93M § 1 to which the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 has transferred such personal data of such corrections; (4) delete personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 provided by, or obtained about, the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1, including personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 provided to the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1, personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 obtained from another source, and derived data and instruct a controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 or processorProcessor"Processor" means a person who collects, processes, or transfers personal data on behalf of, and at the direction of, a controller or another processor, or a Federal, State, Tribal, or local government entity.Ch. 93M § 1 to make reasonable efforts to notify all third parties or processorsProcessor"Processor" means a person who collects, processes, or transfers personal data on behalf of, and at the direction of, a controller or another processor, or a Federal, State, Tribal, or local government entity.Ch. 93M § 1 to which the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 has transferred such personal data of such deletion request; (5) obtain a copy of the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1's personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 collected or processed by the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1, in a portable and, to the extent technically feasible, readily usable format that allows the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 to transmit the data to another controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 without hindrance, where the processing is carried out by automated means;
(a)(6) 2 opt out of the collection and processing of the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1's personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 for purposes of: (i) targeted advertisingTargeted advertising"Targeted advertising" means displaying or presenting an online advertisement to a consumer or to a device identified by a unique persistent identifier (or to a group of consumers or devices identified by unique persistent identifiers), if the advertisement is selected based, in whole or in part, on known or predicted preferences, characteristics, behavior, or interests associated with the consumer or a device identified by a unique persistent identifier. "Targeted advertising" includes displaying or presenting an online advertisement for a product or service based on the previous interaction of a consumer or a device identified by a unique persistent identifier with such product or service on a website or online service that does not share common branding with the website or online service displaying or presenting the advertisement, and marketing measurement related to such advertisements. "Targeted advertising" does not include: (i) first-party advertising; or (ii) contextual advertising.Ch. 93M § 1; (ii) the sale of personal dataSale of personal data"Sale of personal data" means the exchange of personal data for monetary or other valuable consideration by the controller to a third party.Ch. 93M § 1; or (iii) profilingProfiling"Profiling" means any form of processing performed on personal data to evaluate, analyze or predict personal aspects including an individual's economic situation, health, personal preferences, interests, reliability, behavior, location or movements.Ch. 93M § 1 in furtherance of solely automated decisions that produce legal or similarly significant effects concerning the consumerDecisions that produce legal or similarly significant effects concerning the consumer"Decisions that produce legal or similarly significant effects concerning the consumer" means decisions that result in access to, or the provision or denial by the controller of, financial or lending services, housing, insurance, education enrollment or opportunity, criminal justice, employment opportunities, health care services or access to essential goods or services.Ch. 93M § 1.
(b)–(c) 1 A consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 may exercise rights under this section by a secure and reliable means established by the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 and described to the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 in the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1's privacy notice. A consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 may designate an authorized agent in accordance with section 5 of this act to exercise the rights of such consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 specified in this section on behalf of the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1. In the case of personal data of a known child, the parent or legal guardian may exercise such consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 rights on the child's behalf. In the case of personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 concerning a consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 subject to a guardianship, conservatorship or other protective arrangement, the guardian or the conservator of the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 may exercise such rights on the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1's behalf. (c) Except as otherwise provided in this chapter, a controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 shall comply with a request by a consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 to exercise the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 rights authorized pursuant to said sections as follows: (1) A controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 shall respond to the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 without undue delay, but not later than 45 days after receipt of the request. The controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 may extend the response period by 20 additional days when reasonably necessary, considering the complexity and number of the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1's requests, provided the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 informs the consumer of any such extension within the initial 45-day response period and of the reason for the extension. (2) If a controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 declines to take action regarding the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1's request, the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 shall inform the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 without undue delay, but not later than 45 days after receipt of the request, of the justification for declining to take action and instructions for how to appeal the decision. (3) Information provided in response to a consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 request shall be provided by a controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1, free of charge, not less than twice per consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 during any twelve-month period. If requests from a consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 are manifestly unfounded, excessive or repetitive, the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 may charge the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 a reasonable fee to cover the administrative costs of complying with the request or decline to act on the request. The controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 bears the burden of demonstrating the manifestly unfounded, excessive or repetitive nature of the request. (4) If a controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 is unable to authenticate a request to exercise any of the rights afforded under paragraphs (1) to (5), inclusive, of subsection (a) of this section using commercially reasonable efforts, the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 shall not be required to comply with a request to initiate an action pursuant to this section and shall provide notice to the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 that the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 is unable to authenticate the request to exercise such right or rights until such consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 provides additional information reasonably necessary to authenticate such consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 and such consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1's request to exercise such right or rights, provided that any such information may not be used for any purposes other than the authentication of such consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1. A controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 shall not require authentication to exercise an opt-out request, but a controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 may deny an opt-out request if the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 has a good faith, reasonable and documented belief that such request is fraudulent. (5) A controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 that has obtained personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 about a consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 from a source other than the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 shall be deemed in compliance with a consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1's request to delete such data pursuant to paragraph (4) of subsection (a) of this section by deleting the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1's personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 retained by the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 and retaining a record of the deletion request and the minimum data necessary for the purpose of ensuring the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1's personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 remains deleted from the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1's records and not using such retained data for any other purpose pursuant to this chapter.
(d) 3 A controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 shall establish a process for a consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 to appeal the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1's refusal to take action on a request within a reasonable period of time after the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1's receipt of the decision. The appeal process shall be conspicuously available and similar to the process for submitting requests to initiate action pursuant to this section. Not later than 60 days after receipt of an appeal, a controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 shall inform the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 in writing of any action taken or not taken in response to the appeal, including a written explanation of the reasons for the decisions. If the appeal is denied, the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 shall also provide the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 with an online mechanism, if available, or other method through which the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 may contact the attorney general to submit a complaint.
(e)–(f) 4 A controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 may not condition, effectively condition, attempt to condition, or attempt to effectively condition the exercise of a right described in this section through— (1) the use of any false, fictitious, fraudulent, or materially misleading statement or representation; or (2) the use of dark patternsDark pattern"Dark pattern" means a user interface designed or manipulated with the substantial effect of subverting or impairing user autonomy, decision-making or choice, and includes, but is not limited to, any practice the Federal Trade Commission refers to as a "dark pattern".Ch. 93M § 1. (f) A controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 or processorProcessor"Processor" means a person who collects, processes, or transfers personal data on behalf of, and at the direction of, a controller or another processor, or a Federal, State, Tribal, or local government entity.Ch. 93M § 1 may not collect, process, or transfer personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 in a manner that discriminates against an individual or class of individuals, or otherwise makes unavailable the equal enjoyment of goods or services, on the basis of an individual's or class of individuals' actual or perceived race, color, sex, sexual orientation, gender identity, disability, religion, genetic information, pregnancy or condition related to pregnancy, status as a veteran, ancestry or national origin, or any other basis protected by chapter 151B.
Section 4 establishes the core consumer rights: confirmation and access (including inferences), third-party recipient lists, correction with downstream notification, deletion with downstream notification, portability, and opt-out rights for targeted advertising, data sales, and profiling for solely automated consequential decisions. Controllers must respond within 45 days (extendable by 20 days), provide at least two free responses per year, and establish an appeal process with a 60-day decision window. Controllers may not condition rights exercise through dark patterns or misleading statements, and may not discriminate or retaliate against consumers who exercise rights. A nondiscrimination provision prohibits processing personal data in a manner that discriminates on the basis of protected characteristics.
A consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 may designate another person to serve as the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1's authorized agent, and act on such consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1's behalf, to exercise rights specified in subsection (a) of section 4 of this act. A controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 shall comply with a request received from an authorized agent if the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 is able to verify, with commercially reasonable effort, the identity of the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 and the authorized agent's authority to act on such consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1's behalf.
Section 5 permits consumers to designate an authorized agent to exercise their data rights. Controllers must comply with agent requests where the controller can verify both the consumer's identity and the agent's authority with commercially reasonable effort.
(a)(1)–(3) 5 A controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 shall: (1) limit the collection of personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 to what is reasonably necessary and proportionate to provide or maintain a specific product or service requested by the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 to whom the data pertains, including any routine administrative, operational, or account-servicing activity, such as billing, shipping, delivery, storage, accounting, or sending communications; (2) not process or transfer personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 concerning a consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 in a manner that is inconsistent with the reasonable expectations of the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1; (3) not collect, process, or transfer sensitive dataSensitive data"Sensitive data" means personal data that includes: (i) data revealing a consumer's (A) racial or ethnic origin, color, national origin or citizenship or immigration status; (B) religious beliefs; (C) mental or physical health condition, diagnosis, disability or treatment, including, but not limited to, gender-affirming health data, reproductive or sexual health data or legally-protected health care data; (D) sex life, sexual orientation, status as transgender or non-binary; (E) union membership; (F) status as a victim of a crime; or (G) status as a military servicemember or veteran; (ii) consumer health and wellness data; (iii) genetic, neural, or biometric data; (iv) personal data of a consumer that a controller knows, or willfully disregards, is a minor; (v) precise geolocation data; (vi) a government-issued identifier, including a Social Security number, passport number or driver's license number, that is not required by law to be displayed in public; or (vii) account names, passwords, usernames, access codes, security questions or answers, or other credentials and information used to log in to an account or device.Ch. 93M § 1 concerning a consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 except when such collection, processing, or transfer is strictly necessary to provide or maintain a specific product or service requested by the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 to whom the sensitive dataSensitive data"Sensitive data" means personal data that includes: (i) data revealing a consumer's (A) racial or ethnic origin, color, national origin or citizenship or immigration status; (B) religious beliefs; (C) mental or physical health condition, diagnosis, disability or treatment, including, but not limited to, gender-affirming health data, reproductive or sexual health data or legally-protected health care data; (D) sex life, sexual orientation, status as transgender or non-binary; (E) union membership; (F) status as a victim of a crime; or (G) status as a military servicemember or veteran; (ii) consumer health and wellness data; (iii) genetic, neural, or biometric data; (iv) personal data of a consumer that a controller knows, or willfully disregards, is a minor; (v) precise geolocation data; (vi) a government-issued identifier, including a Social Security number, passport number or driver's license number, that is not required by law to be displayed in public; or (vii) account names, passwords, usernames, access codes, security questions or answers, or other credentials and information used to log in to an account or device.Ch. 93M § 1 pertains;
(a)(4)–(6) 6 not sell: (i) precise geolocation dataPrecise geolocation data"Precise geolocation data" means information derived from technology, including, but not limited to, latitude and longitude coordinates from global positioning system mechanisms or other similar positional data, that reveals the past or present physical location of an individual or device that identifies or is linked or reasonably linkable to 1 or more individuals with precision and accuracy within a radius of 1,750 feet.Ch. 93M § 1 regarding a consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1; or (ii) sensitive dataSensitive data"Sensitive data" means personal data that includes: (i) data revealing a consumer's (A) racial or ethnic origin, color, national origin or citizenship or immigration status; (B) religious beliefs; (C) mental or physical health condition, diagnosis, disability or treatment, including, but not limited to, gender-affirming health data, reproductive or sexual health data or legally-protected health care data; (D) sex life, sexual orientation, status as transgender or non-binary; (E) union membership; (F) status as a victim of a crime; or (G) status as a military servicemember or veteran; (ii) consumer health and wellness data; (iii) genetic, neural, or biometric data; (iv) personal data of a consumer that a controller knows, or willfully disregards, is a minor; (v) precise geolocation data; (vi) a government-issued identifier, including a Social Security number, passport number or driver's license number, that is not required by law to be displayed in public; or (vii) account names, passwords, usernames, access codes, security questions or answers, or other credentials and information used to log in to an account or device.Ch. 93M § 1 other than precise geolocation dataPrecise geolocation data"Precise geolocation data" means information derived from technology, including, but not limited to, latitude and longitude coordinates from global positioning system mechanisms or other similar positional data, that reveals the past or present physical location of an individual or device that identifies or is linked or reasonably linkable to 1 or more individuals with precision and accuracy within a radius of 1,750 feet.Ch. 93M § 1 regarding a consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 without obtaining the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1's affirmative consentAffirmative Consent"Affirmative Consent" means a clear affirmative act signifying a consumer's freely given, specific, informed and unambiguous authorization for an act or practice after having been informed, in response to a specific request from a controller, provided that: (i) the request is provided to the consumer in a clear and conspicuous stand-alone disclosure; (ii) the request includes a description of the processing purpose for which the consumer's consent is sought and: (A) clearly distinguishes between an act or practice that is necessary to fulfill a request of the consumer and an act or practice that is for another purpose; (B) clearly states the specific categories of personal data that the controller intends to collect, process, transfer, or sell under each act or practice; and (C) is written in easy-to-understand language and includes a prominent heading that would enable a reasonable consumer to identify and understand each act or practice; (iii) the request clearly explains the consumer's rights related to consent; (iv) the request is made in a manner reasonably accessible to and usable by consumers with disabilities; (v) the request is made prior to the controller's implementation of the act or practice; (vi) the request is made available to the consumer in each language in which the controller provides a product or service for which authorization is sought; (vii) the option to refuse to give consent is at least as prominent as the option to give consent and the option to refuse to give consent takes the same number of steps or fewer as the option to give consent; and (viii) affirmative consent to an act or practice is not inferred from the inaction of the consumer or the consumer's continued use of a service or product provided by the controller.Ch. 93M § 1; (5) establish, implement and maintain reasonable administrative, technical and physical data security practices to protect the confidentiality, integrity and accessibility of personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 appropriate to the volume and nature of the personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 at issue, including disposing of personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 in accordance with a retention schedule that requires the deletion of personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 when the data is required to be deleted by law or is no longer necessary for the purpose for which the data was collected, processed, or transferred; (6) not transfer or sell sensitive dataSensitive data"Sensitive data" means personal data that includes: (i) data revealing a consumer's (A) racial or ethnic origin, color, national origin or citizenship or immigration status; (B) religious beliefs; (C) mental or physical health condition, diagnosis, disability or treatment, including, but not limited to, gender-affirming health data, reproductive or sexual health data or legally-protected health care data; (D) sex life, sexual orientation, status as transgender or non-binary; (E) union membership; (F) status as a victim of a crime; or (G) status as a military servicemember or veteran; (ii) consumer health and wellness data; (iii) genetic, neural, or biometric data; (iv) personal data of a consumer that a controller knows, or willfully disregards, is a minor; (v) precise geolocation data; (vi) a government-issued identifier, including a Social Security number, passport number or driver's license number, that is not required by law to be displayed in public; or (vii) account names, passwords, usernames, access codes, security questions or answers, or other credentials and information used to log in to an account or device.Ch. 93M § 1 concerning a consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 without obtaining the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1's affirmative consentAffirmative Consent"Affirmative Consent" means a clear affirmative act signifying a consumer's freely given, specific, informed and unambiguous authorization for an act or practice after having been informed, in response to a specific request from a controller, provided that: (i) the request is provided to the consumer in a clear and conspicuous stand-alone disclosure; (ii) the request includes a description of the processing purpose for which the consumer's consent is sought and: (A) clearly distinguishes between an act or practice that is necessary to fulfill a request of the consumer and an act or practice that is for another purpose; (B) clearly states the specific categories of personal data that the controller intends to collect, process, transfer, or sell under each act or practice; and (C) is written in easy-to-understand language and includes a prominent heading that would enable a reasonable consumer to identify and understand each act or practice; (iii) the request clearly explains the consumer's rights related to consent; (iv) the request is made in a manner reasonably accessible to and usable by consumers with disabilities; (v) the request is made prior to the controller's implementation of the act or practice; (vi) the request is made available to the consumer in each language in which the controller provides a product or service for which authorization is sought; (vii) the option to refuse to give consent is at least as prominent as the option to give consent and the option to refuse to give consent takes the same number of steps or fewer as the option to give consent; and (viii) affirmative consent to an act or practice is not inferred from the inaction of the consumer or the consumer's continued use of a service or product provided by the controller.Ch. 93M § 1, or, in the case of the collection or processing of personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 concerning a known child, without collecting or processing such data in accordance with COPPA;
(a)(7)–(9) 7 provide an effective mechanism for a consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 to revoke the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1's affirmative consentAffirmative Consent"Affirmative Consent" means a clear affirmative act signifying a consumer's freely given, specific, informed and unambiguous authorization for an act or practice after having been informed, in response to a specific request from a controller, provided that: (i) the request is provided to the consumer in a clear and conspicuous stand-alone disclosure; (ii) the request includes a description of the processing purpose for which the consumer's consent is sought and: (A) clearly distinguishes between an act or practice that is necessary to fulfill a request of the consumer and an act or practice that is for another purpose; (B) clearly states the specific categories of personal data that the controller intends to collect, process, transfer, or sell under each act or practice; and (C) is written in easy-to-understand language and includes a prominent heading that would enable a reasonable consumer to identify and understand each act or practice; (iii) the request clearly explains the consumer's rights related to consent; (iv) the request is made in a manner reasonably accessible to and usable by consumers with disabilities; (v) the request is made prior to the controller's implementation of the act or practice; (vi) the request is made available to the consumer in each language in which the controller provides a product or service for which authorization is sought; (vii) the option to refuse to give consent is at least as prominent as the option to give consent and the option to refuse to give consent takes the same number of steps or fewer as the option to give consent; and (viii) affirmative consent to an act or practice is not inferred from the inaction of the consumer or the consumer's continued use of a service or product provided by the controller.Ch. 93M § 1 under this chapter that is at least as easy as the mechanism by which the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 provided the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1's affirmative consentAffirmative Consent"Affirmative Consent" means a clear affirmative act signifying a consumer's freely given, specific, informed and unambiguous authorization for an act or practice after having been informed, in response to a specific request from a controller, provided that: (i) the request is provided to the consumer in a clear and conspicuous stand-alone disclosure; (ii) the request includes a description of the processing purpose for which the consumer's consent is sought and: (A) clearly distinguishes between an act or practice that is necessary to fulfill a request of the consumer and an act or practice that is for another purpose; (B) clearly states the specific categories of personal data that the controller intends to collect, process, transfer, or sell under each act or practice; and (C) is written in easy-to-understand language and includes a prominent heading that would enable a reasonable consumer to identify and understand each act or practice; (iii) the request clearly explains the consumer's rights related to consent; (iv) the request is made in a manner reasonably accessible to and usable by consumers with disabilities; (v) the request is made prior to the controller's implementation of the act or practice; (vi) the request is made available to the consumer in each language in which the controller provides a product or service for which authorization is sought; (vii) the option to refuse to give consent is at least as prominent as the option to give consent and the option to refuse to give consent takes the same number of steps or fewer as the option to give consent; and (viii) affirmative consent to an act or practice is not inferred from the inaction of the consumer or the consumer's continued use of a service or product provided by the controller.Ch. 93M § 1 and, upon revocation of such affirmative consentAffirmative Consent"Affirmative Consent" means a clear affirmative act signifying a consumer's freely given, specific, informed and unambiguous authorization for an act or practice after having been informed, in response to a specific request from a controller, provided that: (i) the request is provided to the consumer in a clear and conspicuous stand-alone disclosure; (ii) the request includes a description of the processing purpose for which the consumer's consent is sought and: (A) clearly distinguishes between an act or practice that is necessary to fulfill a request of the consumer and an act or practice that is for another purpose; (B) clearly states the specific categories of personal data that the controller intends to collect, process, transfer, or sell under each act or practice; and (C) is written in easy-to-understand language and includes a prominent heading that would enable a reasonable consumer to identify and understand each act or practice; (iii) the request clearly explains the consumer's rights related to consent; (iv) the request is made in a manner reasonably accessible to and usable by consumers with disabilities; (v) the request is made prior to the controller's implementation of the act or practice; (vi) the request is made available to the consumer in each language in which the controller provides a product or service for which authorization is sought; (vii) the option to refuse to give consent is at least as prominent as the option to give consent and the option to refuse to give consent takes the same number of steps or fewer as the option to give consent; and (viii) affirmative consent to an act or practice is not inferred from the inaction of the consumer or the consumer's continued use of a service or product provided by the controller.Ch. 93M § 1, cease to process the data as soon as practicable, but not later than fifteen days after the receipt of such request; (8) not collect or process the personal data of a consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 for purposes of targeted advertisingTargeted advertising"Targeted advertising" means displaying or presenting an online advertisement to a consumer or to a device identified by a unique persistent identifier (or to a group of consumers or devices identified by unique persistent identifiers), if the advertisement is selected based, in whole or in part, on known or predicted preferences, characteristics, behavior, or interests associated with the consumer or a device identified by a unique persistent identifier. "Targeted advertising" includes displaying or presenting an online advertisement for a product or service based on the previous interaction of a consumer or a device identified by a unique persistent identifier with such product or service on a website or online service that does not share common branding with the website or online service displaying or presenting the advertisement, and marketing measurement related to such advertisements. "Targeted advertising" does not include: (i) first-party advertising; or (ii) contextual advertising.Ch. 93M § 1 or first-party advertising, or sell the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1's personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1, under circumstances where a controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 has actual knowledge, or willfully disregards, that the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 is a minor; and (9) not discriminate or retaliate against a consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 for exercising any of the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 rights contained in this chapter, or for refusing to agree to the collection or processing of personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 for a separate product or service, including denying goods or services, charging different prices or rates for goods or services or providing a different level of quality of goods or services to the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1.
(c) 8 A controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 shall provide consumersConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 with a reasonably accessible, clear and meaningful privacy notice that includes: (1) The categories of personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 collected and processed by the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1, including a separate list of categories of sensitive dataSensitive data"Sensitive data" means personal data that includes: (i) data revealing a consumer's (A) racial or ethnic origin, color, national origin or citizenship or immigration status; (B) religious beliefs; (C) mental or physical health condition, diagnosis, disability or treatment, including, but not limited to, gender-affirming health data, reproductive or sexual health data or legally-protected health care data; (D) sex life, sexual orientation, status as transgender or non-binary; (E) union membership; (F) status as a victim of a crime; or (G) status as a military servicemember or veteran; (ii) consumer health and wellness data; (iii) genetic, neural, or biometric data; (iv) personal data of a consumer that a controller knows, or willfully disregards, is a minor; (v) precise geolocation data; (vi) a government-issued identifier, including a Social Security number, passport number or driver's license number, that is not required by law to be displayed in public; or (vii) account names, passwords, usernames, access codes, security questions or answers, or other credentials and information used to log in to an account or device.Ch. 93M § 1 collected and processed by the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1, described in a level of detail that provides consumersConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 a meaningful understanding of the type of personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 collected or processed; (2) the purpose for collecting and processing each category of personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 collects or processes described in a way that gives consumersConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 a meaningful understanding of how each category of their personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 will be used; (3) how consumersConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 may exercise their consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 rights, including how a consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 may appeal a controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1's decision with regard to the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1's request; (4) the categories of personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 that the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 transfers to third parties, if any, and the purposes for those transfers; (5) the categories of third parties, if any, to which the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 transfers personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1; (6) The length of time the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 intends to retain each category of personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1, or, if it is not possible to identify the length of time, the criteria used to determine the length of time the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 intends to retain categories of personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1; and (7) an active electronic mail address or other online mechanism that the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 may use to contact the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1. The privacy notice shall be provided directly to consumersConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 and made available online to the general public. If a controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 makes a material change to its privacy notice, the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 shall notify each consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 affected by the material change before implementing the material change with respect to prospectively collected personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 and provide a reasonable opportunity for each consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 to withdraw consent.
(d)–(e) 9 If a controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 sells personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 to third parties or processes personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 for targeted advertisingTargeted advertising"Targeted advertising" means displaying or presenting an online advertisement to a consumer or to a device identified by a unique persistent identifier (or to a group of consumers or devices identified by unique persistent identifiers), if the advertisement is selected based, in whole or in part, on known or predicted preferences, characteristics, behavior, or interests associated with the consumer or a device identified by a unique persistent identifier. "Targeted advertising" includes displaying or presenting an online advertisement for a product or service based on the previous interaction of a consumer or a device identified by a unique persistent identifier with such product or service on a website or online service that does not share common branding with the website or online service displaying or presenting the advertisement, and marketing measurement related to such advertisements. "Targeted advertising" does not include: (i) first-party advertising; or (ii) contextual advertising.Ch. 93M § 1, the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 shall clearly and conspicuously disclose such sales or processing, as well as the manner in which a consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 may exercise the right to opt out of such sales or processing. (e) A controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 shall establish, and shall describe in a privacy notice, not less than two secure and reliable means for consumersConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 to submit a request to exercise their consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 rights pursuant to this chapter. Such means shall take into account the ways in which consumersConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 normally interact with the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1, the need for secure and reliable communication of such requests and the ability of the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 to verify the identity of the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 making the request. A controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 shall not require a consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 to create a new account in order to exercise consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 rights, but may require a consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 to use an existing account. Any such means shall include: (1) Providing a clear and conspicuous link on the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1's Internet web site to an Internet web page that enables a consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1, or an agent of the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1, to opt out of the targeted advertisingTargeted advertising"Targeted advertising" means displaying or presenting an online advertisement to a consumer or to a device identified by a unique persistent identifier (or to a group of consumers or devices identified by unique persistent identifiers), if the advertisement is selected based, in whole or in part, on known or predicted preferences, characteristics, behavior, or interests associated with the consumer or a device identified by a unique persistent identifier. "Targeted advertising" includes displaying or presenting an online advertisement for a product or service based on the previous interaction of a consumer or a device identified by a unique persistent identifier with such product or service on a website or online service that does not share common branding with the website or online service displaying or presenting the advertisement, and marketing measurement related to such advertisements. "Targeted advertising" does not include: (i) first-party advertising; or (ii) contextual advertising.Ch. 93M § 1, the sale of the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1's personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1, and profilingProfiling"Profiling" means any form of processing performed on personal data to evaluate, analyze or predict personal aspects including an individual's economic situation, health, personal preferences, interests, reliability, behavior, location or movements.Ch. 93M § 1 in furtherance of solely automated decisions that produce legal or similarly significant effects concerning the consumerDecisions that produce legal or similarly significant effects concerning the consumer"Decisions that produce legal or similarly significant effects concerning the consumer" means decisions that result in access to, or the provision or denial by the controller of, financial or lending services, housing, insurance, education enrollment or opportunity, criminal justice, employment opportunities, health care services or access to essential goods or services.Ch. 93M § 1; and (2) Not later than 18 months after the effective date of this chapter, allowing a consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 to opt out of any collection or processing of the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1's personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 for the purposes of targeted advertisingTargeted advertising"Targeted advertising" means displaying or presenting an online advertisement to a consumer or to a device identified by a unique persistent identifier (or to a group of consumers or devices identified by unique persistent identifiers), if the advertisement is selected based, in whole or in part, on known or predicted preferences, characteristics, behavior, or interests associated with the consumer or a device identified by a unique persistent identifier. "Targeted advertising" includes displaying or presenting an online advertisement for a product or service based on the previous interaction of a consumer or a device identified by a unique persistent identifier with such product or service on a website or online service that does not share common branding with the website or online service displaying or presenting the advertisement, and marketing measurement related to such advertisements. "Targeted advertising" does not include: (i) first-party advertising; or (ii) contextual advertising.Ch. 93M § 1, or any sale of the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1's personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1, through an opt-out preference signal sent, with such consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1's consent, by a platform, technology or mechanism to the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 indicating such consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1's intent to opt out of any such processing or sale.
Section 6 imposes the bill's core affirmative obligations on controllers. Controllers must practice data minimization, limit processing to consumer expectations, restrict sensitive data to strict necessity, prohibit sale of precise geolocation data outright and other sensitive data without affirmative consent, maintain data security practices, provide a consent revocation mechanism (with 15-day processing deadline), prohibit targeted advertising, first-party advertising, and data sales for known minors, and refrain from discrimination or retaliation. Controllers must publish detailed privacy notices with enumerated content requirements and provide direct notification of material changes. Controllers must provide at least two mechanisms for rights exercise including a clear opt-out link and, within 18 months, support for opt-out preference signals. The opt-out signal must override conflicting controller-specific settings.
(a)–(b) 10 A processorProcessor"Processor" means a person who collects, processes, or transfers personal data on behalf of, and at the direction of, a controller or another processor, or a Federal, State, Tribal, or local government entity.Ch. 93M § 1 shall adhere to the instructions of a controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 and shall assist the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 in meeting the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1's obligations under this chapter. Such assistance shall include: (1) taking into account the nature of processing and the information available to the processorProcessor"Processor" means a person who collects, processes, or transfers personal data on behalf of, and at the direction of, a controller or another processor, or a Federal, State, Tribal, or local government entity.Ch. 93M § 1, by appropriate technical and organizational measures, insofar as is reasonably practicable, to fulfill the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1's obligation to respond to consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 rights requests; (2) taking into account the nature of processing and the information available to the processorProcessor"Processor" means a person who collects, processes, or transfers personal data on behalf of, and at the direction of, a controller or another processor, or a Federal, State, Tribal, or local government entity.Ch. 93M § 1, by assisting the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 in meeting the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1's obligations in relation to the security of processing the personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 and in relation to the notification of a breach of security of the system of the processorProcessor"Processor" means a person who collects, processes, or transfers personal data on behalf of, and at the direction of, a controller or another processor, or a Federal, State, Tribal, or local government entity.Ch. 93M § 1, in order to meet the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1's obligations; and (3) providing necessary information to enable the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 to conduct and document data protection assessments. (b) A contract between a controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 and a processorProcessor"Processor" means a person who collects, processes, or transfers personal data on behalf of, and at the direction of, a controller or another processor, or a Federal, State, Tribal, or local government entity.Ch. 93M § 1 shall govern the processorProcessor"Processor" means a person who collects, processes, or transfers personal data on behalf of, and at the direction of, a controller or another processor, or a Federal, State, Tribal, or local government entity.Ch. 93M § 1's data processing procedures with respect to processing performed on behalf of the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1. The contract shall be written, binding and clearly set forth instructions for processing data, the nature and purpose of processing, the type of data subject to processing, the duration of processing and the rights and obligations of both parties including a method by which the processorProcessor"Processor" means a person who collects, processes, or transfers personal data on behalf of, and at the direction of, a controller or another processor, or a Federal, State, Tribal, or local government entity.Ch. 93M § 1 shall notify the covered entity of material changes to its privacy practices. The processorProcessor"Processor" means a person who collects, processes, or transfers personal data on behalf of, and at the direction of, a controller or another processor, or a Federal, State, Tribal, or local government entity.Ch. 93M § 1 shall adhere to the instructions of the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 and only process and transfer the data it receives from the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 to the extent necessary to provide a service requested by the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1, as set out in the contract. The contract shall also require that the processorProcessor"Processor" means a person who collects, processes, or transfers personal data on behalf of, and at the direction of, a controller or another processor, or a Federal, State, Tribal, or local government entity.Ch. 93M § 1: (1) Ensure that each person processing personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 is subject to a duty of confidentiality with respect to the data; (2) at the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1's direction, delete or return all personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 to the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 as requested at the end of the provision of services, unless retention of the personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 is required by law; (3) upon the reasonable request of the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1, make available to the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 all information in its possession necessary to demonstrate the processorProcessor"Processor" means a person who collects, processes, or transfers personal data on behalf of, and at the direction of, a controller or another processor, or a Federal, State, Tribal, or local government entity.Ch. 93M § 1's compliance with the obligations in this chapter; (4) after providing the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 an opportunity to object, engage any subcontractor pursuant to a written contract that requires the subcontractor to meet the contractual and statutory or regulatory obligations of the processorProcessor"Processor" means a person who collects, processes, or transfers personal data on behalf of, and at the direction of, a controller or another processor, or a Federal, State, Tribal, or local government entity.Ch. 93M § 1 with respect to the personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1; (5) be prohibited from combining personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 that the processorProcessor"Processor" means a person who collects, processes, or transfers personal data on behalf of, and at the direction of, a controller or another processor, or a Federal, State, Tribal, or local government entity.Ch. 93M § 1 receives from or on behalf of a controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 with personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 that the processorProcessor"Processor" means a person who collects, processes, or transfers personal data on behalf of, and at the direction of, a controller or another processor, or a Federal, State, Tribal, or local government entity.Ch. 93M § 1 receives from or on behalf of another person or collects from the interaction of the processorProcessor"Processor" means a person who collects, processes, or transfers personal data on behalf of, and at the direction of, a controller or another processor, or a Federal, State, Tribal, or local government entity.Ch. 93M § 1 with an individual; and (6) allow, and cooperate with, reasonable assessments by the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 or the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1's designated assessor, or the processorProcessor"Processor" means a person who collects, processes, or transfers personal data on behalf of, and at the direction of, a controller or another processor, or a Federal, State, Tribal, or local government entity.Ch. 93M § 1 may arrange for a qualified and independent assessor to conduct an assessment of the processorProcessor"Processor" means a person who collects, processes, or transfers personal data on behalf of, and at the direction of, a controller or another processor, or a Federal, State, Tribal, or local government entity.Ch. 93M § 1's policies and technical and organizational measures in support of the obligations under this chapter, using an appropriate and accepted control standard or framework and assessment procedure for such assessments.
(c) 10 A processorProcessor"Processor" means a person who collects, processes, or transfers personal data on behalf of, and at the direction of, a controller or another processor, or a Federal, State, Tribal, or local government entity.Ch. 93M § 1 shall establish, implement and maintain reasonable administrative, technical and physical data security practices to protect the confidentiality, integrity and accessibility of personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 that are consistent with chapter 93H and appropriate to the volume and nature of the personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 at issue.
(e)–(f) Determining whether a person is acting as a controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 or processorProcessor"Processor" means a person who collects, processes, or transfers personal data on behalf of, and at the direction of, a controller or another processor, or a Federal, State, Tribal, or local government entity.Ch. 93M § 1 with respect to a specific processing of data is a fact-based determination that depends upon the context in which personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 is to be processed. A person who is not limited in such person's processing of personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 pursuant to a controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1's instructions, or who fails to adhere to such instructions, is a controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 and not a processorProcessor"Processor" means a person who collects, processes, or transfers personal data on behalf of, and at the direction of, a controller or another processor, or a Federal, State, Tribal, or local government entity.Ch. 93M § 1 with respect to a specific processing of data. A processorProcessor"Processor" means a person who collects, processes, or transfers personal data on behalf of, and at the direction of, a controller or another processor, or a Federal, State, Tribal, or local government entity.Ch. 93M § 1 that continues to adhere to a controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1's instructions with respect to a specific processing of personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 remains a processorProcessor"Processor" means a person who collects, processes, or transfers personal data on behalf of, and at the direction of, a controller or another processor, or a Federal, State, Tribal, or local government entity.Ch. 93M § 1. If a processorProcessor"Processor" means a person who collects, processes, or transfers personal data on behalf of, and at the direction of, a controller or another processor, or a Federal, State, Tribal, or local government entity.Ch. 93M § 1 begins, alone or jointly with others, determining the purposes and means of the processing of personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1, the processorProcessor"Processor" means a person who collects, processes, or transfers personal data on behalf of, and at the direction of, a controller or another processor, or a Federal, State, Tribal, or local government entity.Ch. 93M § 1 is a controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 with respect to such processing and may be subject to an enforcement action under this chapter. (f) A processorProcessor"Processor" means a person who collects, processes, or transfers personal data on behalf of, and at the direction of, a controller or another processor, or a Federal, State, Tribal, or local government entity.Ch. 93M § 1 shall not process or transfer personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 on the behalf of a controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 if the processorProcessor"Processor" means a person who collects, processes, or transfers personal data on behalf of, and at the direction of, a controller or another processor, or a Federal, State, Tribal, or local government entity.Ch. 93M § 1 has actual knowledge that the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 has violated this chapter with respect to such personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1.
Section 7 establishes the processor-controller contractual and operational relationship. Processors must adhere to controller instructions and assist with consumer rights fulfillment, security obligations, and data protection assessments. Controller-processor contracts must be written and specify processing instructions, purpose, data types, duration, and mutual obligations. Processors must maintain confidentiality, delete or return data at service end, demonstrate compliance, use subcontractors only under written contracts, and not combine data across controllers. Processors must maintain their own data security practices. A processor that begins determining processing purposes becomes a controller subject to enforcement.
(a) 11 A controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 shall not conduct processing that presents a heightened risk of harm to a consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 without conducting and documenting a data protection assessment for each of the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1's processing activities that presents such heightened risk of harm to a consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1. For the purposes of this section, processing that presents a heightened risk of harm to a consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 includes: (1) The collection or processing of personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 for the purposes of targeted advertisingTargeted advertising"Targeted advertising" means displaying or presenting an online advertisement to a consumer or to a device identified by a unique persistent identifier (or to a group of consumers or devices identified by unique persistent identifiers), if the advertisement is selected based, in whole or in part, on known or predicted preferences, characteristics, behavior, or interests associated with the consumer or a device identified by a unique persistent identifier. "Targeted advertising" includes displaying or presenting an online advertisement for a product or service based on the previous interaction of a consumer or a device identified by a unique persistent identifier with such product or service on a website or online service that does not share common branding with the website or online service displaying or presenting the advertisement, and marketing measurement related to such advertisements. "Targeted advertising" does not include: (i) first-party advertising; or (ii) contextual advertising.Ch. 93M § 1; (2) the sale of personal dataSale of personal data"Sale of personal data" means the exchange of personal data for monetary or other valuable consideration by the controller to a third party.Ch. 93M § 1; (3) the processing of personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 for the purposes of profilingProfiling"Profiling" means any form of processing performed on personal data to evaluate, analyze or predict personal aspects including an individual's economic situation, health, personal preferences, interests, reliability, behavior, location or movements.Ch. 93M § 1, where such profilingProfiling"Profiling" means any form of processing performed on personal data to evaluate, analyze or predict personal aspects including an individual's economic situation, health, personal preferences, interests, reliability, behavior, location or movements.Ch. 93M § 1 presents a reasonably foreseeable risk of: (i) unfair or deceptive treatment of, or unlawful disparate impact on, consumersConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1, (ii) financial, physical or reputational injury to consumersConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1, (iii) a physical or other intrusion upon the solitude or seclusion, or the private affairs or concerns, of consumersConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1, where such intrusion would be offensive to a reasonable person, or (iv) other substantial injury to consumersConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1; (4) the collection or processing of sensitive dataSensitive data"Sensitive data" means personal data that includes: (i) data revealing a consumer's (A) racial or ethnic origin, color, national origin or citizenship or immigration status; (B) religious beliefs; (C) mental or physical health condition, diagnosis, disability or treatment, including, but not limited to, gender-affirming health data, reproductive or sexual health data or legally-protected health care data; (D) sex life, sexual orientation, status as transgender or non-binary; (E) union membership; (F) status as a victim of a crime; or (G) status as a military servicemember or veteran; (ii) consumer health and wellness data; (iii) genetic, neural, or biometric data; (iv) personal data of a consumer that a controller knows, or willfully disregards, is a minor; (v) precise geolocation data; (vi) a government-issued identifier, including a Social Security number, passport number or driver's license number, that is not required by law to be displayed in public; or (vii) account names, passwords, usernames, access codes, security questions or answers, or other credentials and information used to log in to an account or device.Ch. 93M § 1; and (5) the collection or processing of personal information collected via a consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1's use of a product or service predominantly used by minors.
(b) 11 Data protection assessments conducted pursuant to subsection (a) of this section shall identify the categories of personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 collected, the purposes for collecting such personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1, whether personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 is being transferred and identify and weigh the benefits that may flow, directly and indirectly, from the processing to the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1, the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1, other stakeholders and the public against the potential risks to the rights of the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 associated with such processing, as mitigated by safeguards that are employed by the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 to reduce such risks. The controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 shall factor into any such data protection assessment the use of de-identified dataDe-identified data"De-identified data" means data that does not identify and cannot reasonably be used to infer information about, or otherwise be linked to, an identified or identifiable individual, or a device linked to such individual, if the controller that possesses such data: (i) takes reasonable physical, administrative, and technical measures to ensure that such data cannot be associated with an individual or be used to re-identify any individual or device that identifies or is linked or reasonably linkable to an individual, (ii) publicly commits to process such data only in a de-identified fashion and not attempt to re-identify such data, and (iii) contractually obligates any recipients of such data to satisfy the criteria set forth in subparagraphs (i) and (ii) of this definition.Ch. 93M § 1 and the reasonable expectations of consumersConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1, as well as the context of the processing and the relationship between the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 and the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 whose personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 will be processed.
(c) 12 No later than 30 days after completing a data protection assessment under this section, a controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 shall submit a report of the data protection assessment or evaluation to the attorney general. The report must include a summary of the data protection assessment and the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 shall make the summary publicly available in a place that is easily accessible to consumersConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1. ControllersController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 may redact trade secrets or other confidential or proprietary information from the report. The attorney general may require that a controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 disclose any data protection assessment that is relevant to an investigation conducted by the attorney general, and the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 shall make the data protection assessment available to the attorney general. The attorney general may evaluate the data protection assessment for compliance with the responsibilities set forth in this chapter. To the extent any information contained in a data protection assessment disclosed to the attorney general includes information subject to attorney-client privilege or work product protection, such disclosure shall not constitute a waiver of such privilege or protection.
(f) 13 A controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 shall review and update the data protection assessment as often as appropriate considering the type, amount, and sensitivity of personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 collected or processed and level of risk presented by the processing, throughout the processing activity's lifecycle in order to: (1) monitor for harm caused by the processing and adjust safeguards accordingly; and (2) ensure that data protection and privacy are considered as the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 makes new decisions with respect to the processing.
Section 8 requires controllers to conduct and document data protection assessments before engaging in processing that presents a heightened risk of harm. Covered activities include targeted advertising, data sales, profiling with foreseeable risks of unfair treatment or injury, sensitive data processing, and processing data from products predominantly used by minors. Assessments must identify categories of data collected, weigh benefits against consumer risks, and factor in de-identification and consumer expectations. Assessments must be filed with the attorney general within 30 days, and summaries must be publicly posted. The AG may demand full assessments in investigations. Assessments must be reviewed and updated throughout the processing lifecycle. The first assessments must be completed within one year of the effective date.
(a)–(d) 14 Any controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 in possession of de-identified dataDe-identified data"De-identified data" means data that does not identify and cannot reasonably be used to infer information about, or otherwise be linked to, an identified or identifiable individual, or a device linked to such individual, if the controller that possesses such data: (i) takes reasonable physical, administrative, and technical measures to ensure that such data cannot be associated with an individual or be used to re-identify any individual or device that identifies or is linked or reasonably linkable to an individual, (ii) publicly commits to process such data only in a de-identified fashion and not attempt to re-identify such data, and (iii) contractually obligates any recipients of such data to satisfy the criteria set forth in subparagraphs (i) and (ii) of this definition.Ch. 93M § 1 shall: (1) Take technical measures to ensure that the data cannot be associated with an individual; (2) publicly commit to maintaining and using de-identified dataDe-identified data"De-identified data" means data that does not identify and cannot reasonably be used to infer information about, or otherwise be linked to, an identified or identifiable individual, or a device linked to such individual, if the controller that possesses such data: (i) takes reasonable physical, administrative, and technical measures to ensure that such data cannot be associated with an individual or be used to re-identify any individual or device that identifies or is linked or reasonably linkable to an individual, (ii) publicly commits to process such data only in a de-identified fashion and not attempt to re-identify such data, and (iii) contractually obligates any recipients of such data to satisfy the criteria set forth in subparagraphs (i) and (ii) of this definition.Ch. 93M § 1 without attempting to re-identify the data; and (3) contractually obligate any recipients of the de-identified dataDe-identified data"De-identified data" means data that does not identify and cannot reasonably be used to infer information about, or otherwise be linked to, an identified or identifiable individual, or a device linked to such individual, if the controller that possesses such data: (i) takes reasonable physical, administrative, and technical measures to ensure that such data cannot be associated with an individual or be used to re-identify any individual or device that identifies or is linked or reasonably linkable to an individual, (ii) publicly commits to process such data only in a de-identified fashion and not attempt to re-identify such data, and (iii) contractually obligates any recipients of such data to satisfy the criteria set forth in subparagraphs (i) and (ii) of this definition.Ch. 93M § 1 to comply with all provisions of this chapter. (b) Nothing in this chapter shall be construed to: (1) Require a controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 or processorProcessor"Processor" means a person who collects, processes, or transfers personal data on behalf of, and at the direction of, a controller or another processor, or a Federal, State, Tribal, or local government entity.Ch. 93M § 1 to re-identify de-identified dataDe-identified data"De-identified data" means data that does not identify and cannot reasonably be used to infer information about, or otherwise be linked to, an identified or identifiable individual, or a device linked to such individual, if the controller that possesses such data: (i) takes reasonable physical, administrative, and technical measures to ensure that such data cannot be associated with an individual or be used to re-identify any individual or device that identifies or is linked or reasonably linkable to an individual, (ii) publicly commits to process such data only in a de-identified fashion and not attempt to re-identify such data, and (iii) contractually obligates any recipients of such data to satisfy the criteria set forth in subparagraphs (i) and (ii) of this definition.Ch. 93M § 1; or (2) maintain data in identifiable form, or collect, obtain, retain or access any data or technology, in order to be capable of associating an authenticated consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 request with personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1. (c) Nothing in this chapter shall be construed to require a controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 or processorProcessor"Processor" means a person who collects, processes, or transfers personal data on behalf of, and at the direction of, a controller or another processor, or a Federal, State, Tribal, or local government entity.Ch. 93M § 1 to comply with an authenticated consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 rights request if the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1: (1) is not reasonably capable of associating the request with the personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 or it would be unreasonably burdensome for the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 to associate the request with the personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1; and (2) does not use the personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 to recognize or respond to the specific consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 who is the subject of the personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1, or associate the personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 with other personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 about the same specific consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1; (d) A controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 that transfers de-identified dataDe-identified data"De-identified data" means data that does not identify and cannot reasonably be used to infer information about, or otherwise be linked to, an identified or identifiable individual, or a device linked to such individual, if the controller that possesses such data: (i) takes reasonable physical, administrative, and technical measures to ensure that such data cannot be associated with an individual or be used to re-identify any individual or device that identifies or is linked or reasonably linkable to an individual, (ii) publicly commits to process such data only in a de-identified fashion and not attempt to re-identify such data, and (iii) contractually obligates any recipients of such data to satisfy the criteria set forth in subparagraphs (i) and (ii) of this definition.Ch. 93M § 1 shall exercise reasonable oversight to monitor compliance with any contractual commitments to which the de-identified dataDe-identified data"De-identified data" means data that does not identify and cannot reasonably be used to infer information about, or otherwise be linked to, an identified or identifiable individual, or a device linked to such individual, if the controller that possesses such data: (i) takes reasonable physical, administrative, and technical measures to ensure that such data cannot be associated with an individual or be used to re-identify any individual or device that identifies or is linked or reasonably linkable to an individual, (ii) publicly commits to process such data only in a de-identified fashion and not attempt to re-identify such data, and (iii) contractually obligates any recipients of such data to satisfy the criteria set forth in subparagraphs (i) and (ii) of this definition.Ch. 93M § 1 is subject and shall take appropriate steps to address any breaches of those contractual commitments.
Section 9 imposes safeguards on controllers possessing de-identified data: they must implement technical measures to prevent re-identification, publicly commit to maintaining the data in de-identified form, and contractually bind recipients. Controllers need not re-identify data to comply with consumer rights requests, and controllers that cannot reasonably associate a request with personal data are excused from compliance for that data. Controllers transferring de-identified data must monitor recipient compliance and address breaches.
(a)–(f) Nothing in this chapter shall be construed to restrict a controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1's or processorProcessor"Processor" means a person who collects, processes, or transfers personal data on behalf of, and at the direction of, a controller or another processor, or a Federal, State, Tribal, or local government entity.Ch. 93M § 1's ability to: (1) Comply with federal, state or municipal ordinances or regulations; (2) comply with a civil, criminal or regulatory inquiry, investigation, subpoena or summons by federal, state, municipal or other governmental authorities, except as prohibited by another law, including, but not limited to, section 115 of chapter 93; (3) cooperate with law enforcement agencies concerning conduct or activity that the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 or processorProcessor"Processor" means a person who collects, processes, or transfers personal data on behalf of, and at the direction of, a controller or another processor, or a Federal, State, Tribal, or local government entity.Ch. 93M § 1 reasonably and in good faith believes may violate federal, state or municipal ordinances or regulations; (4) investigate, establish, exercise, prepare for or defend legal claims; (5) provide, maintain, improve, or update a product or service specifically requested by the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1; (6) perform under a contract to which a consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 is a party, including fulfilling the terms of a written warranty; (7) take steps at the request of a consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 prior to entering into a contract; (8) take immediate steps to protect an interest that is essential for the life or physical safety of the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 or another individual, and where the processing cannot be manifestly based on another legal basis; (9) prevent, detect, protect against or respond to security incidents, identity theft, fraud, harassment, malicious or deceptive activities or any illegal activity targeted at or involving the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 or processorProcessor"Processor" means a person who collects, processes, or transfers personal data on behalf of, and at the direction of, a controller or another processor, or a Federal, State, Tribal, or local government entity.Ch. 93M § 1 or its services, preserve the integrity or security of systems or investigate, report or prosecute those responsible for any such action; (10) engage in public or peer-reviewed scientific, historical, or statistical research in the public interest; (11) assist another controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1, processorProcessor"Processor" means a person who collects, processes, or transfers personal data on behalf of, and at the direction of, a controller or another processor, or a Federal, State, Tribal, or local government entity.Ch. 93M § 1 or third party with any of the obligations under this chapter; (12) process personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 for reasons of public interest in the area of public health, community health or population health; (13) ensure the data security and integrity of personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1; (14) effectuate a product recall; (15) conduct medical research in compliance with applicable CFR; (16) publish entity-based member or employee contact information; (17) process personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 to become de-identified dataDe-identified data"De-identified data" means data that does not identify and cannot reasonably be used to infer information about, or otherwise be linked to, an identified or identifiable individual, or a device linked to such individual, if the controller that possesses such data: (i) takes reasonable physical, administrative, and technical measures to ensure that such data cannot be associated with an individual or be used to re-identify any individual or device that identifies or is linked or reasonably linkable to an individual, (ii) publicly commits to process such data only in a de-identified fashion and not attempt to re-identify such data, and (iii) contractually obligates any recipients of such data to satisfy the criteria set forth in subparagraphs (i) and (ii) of this definition.Ch. 93M § 1; or (18) provide information or feedback to the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1. (b) The obligations imposed on controllersController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 or processorsProcessor"Processor" means a person who collects, processes, or transfers personal data on behalf of, and at the direction of, a controller or another processor, or a Federal, State, Tribal, or local government entity.Ch. 93M § 1 under this chapter shall not apply where compliance would violate an evidentiary privilege.(c) A controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 or processorProcessor"Processor" means a person who collects, processes, or transfers personal data on behalf of, and at the direction of, a controller or another processor, or a Federal, State, Tribal, or local government entity.Ch. 93M § 1 that discloses personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 to a processorProcessor"Processor" means a person who collects, processes, or transfers personal data on behalf of, and at the direction of, a controller or another processor, or a Federal, State, Tribal, or local government entity.Ch. 93M § 1 or third-party controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 in accordance with this chapter shall not be deemed to have violated said sections if the processorProcessor"Processor" means a person who collects, processes, or transfers personal data on behalf of, and at the direction of, a controller or another processor, or a Federal, State, Tribal, or local government entity.Ch. 93M § 1 or third-party controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 that receives and processes such personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 violates said sections, provided, at the time the disclosing controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 or processorProcessor"Processor" means a person who collects, processes, or transfers personal data on behalf of, and at the direction of, a controller or another processor, or a Federal, State, Tribal, or local government entity.Ch. 93M § 1 disclosed such personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1, the disclosing controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 or processorProcessor"Processor" means a person who collects, processes, or transfers personal data on behalf of, and at the direction of, a controller or another processor, or a Federal, State, Tribal, or local government entity.Ch. 93M § 1 did not have actual knowledge that the receiving processorProcessor"Processor" means a person who collects, processes, or transfers personal data on behalf of, and at the direction of, a controller or another processor, or a Federal, State, Tribal, or local government entity.Ch. 93M § 1 or third-party controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 would violate said sections. (d) Nothing in this chapter shall be construed to: (1) Impose any obligation on a controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 or processorProcessor"Processor" means a person who collects, processes, or transfers personal data on behalf of, and at the direction of, a controller or another processor, or a Federal, State, Tribal, or local government entity.Ch. 93M § 1 that adversely affects the rights or freedoms of any person, including, but not limited to, the rights of any person to freedom of speech or freedom of the press guaranteed in the First Amendment to the United States Constitution or Article 16 of the Massachusetts Declaration of Rights; (2) apply to any person's collection or processing of personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 in the course of such person's purely personal or household activities; or (3) for private schools approved under section 1 of chapter 76 and private institutions of higher education, require deletion of personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 that would unreasonably interfere with the provision of education services. (e) Personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 collected or processed by a controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 pursuant to this section may be collected or processed to the extent that such collection and processing is: (1) Reasonably necessary and proportionate to the purposes listed in this section; (2) limited to what is necessary in relation to the specific purposes; and (3) compliant with subsection (f) of section 4. (f) If a controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 collects or processes personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 pursuant to an exemption in this section, the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 bears the burden of demonstrating that such collection or processing qualifies for the exemption.
Section 10 enumerates exceptions to the chapter's obligations. Controllers and processors may process data for law enforcement cooperation, legal claims, regulatory compliance, security incident prevention, public interest research (with IRB oversight), public health processing, product recalls, medical research, and other specified purposes. The section preserves evidentiary privileges, exempts purely personal or household activities, and protects private schools from deletion mandates that would unreasonably interfere with education. Data processed under these exceptions must still meet proportionality and security requirements and comply with the nondiscrimination provision.
(a) The attorney general may promulgate rules and regulations to implement this Act, including, but not limited to, rules and regulations that: (1) establish or adopt baseline technical requirements that determine if a given dataset has been or can be considered sufficiently de-identified; (2) establish reasonable administrative, technical and physical data security practices that satisfy the requirements set forward in paragraph (5) of subsection (a) of section 6; (3) establish a nonexclusive list of practices that constitute dark patternsDark pattern"Dark pattern" means a user interface designed or manipulated with the substantial effect of subverting or impairing user autonomy, decision-making or choice, and includes, but is not limited to, any practice the Federal Trade Commission refers to as a "dark pattern".Ch. 93M § 1 or otherwise violate the requirements of this chapter regarding a consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1's affirmative consentAffirmative Consent"Affirmative Consent" means a clear affirmative act signifying a consumer's freely given, specific, informed and unambiguous authorization for an act or practice after having been informed, in response to a specific request from a controller, provided that: (i) the request is provided to the consumer in a clear and conspicuous stand-alone disclosure; (ii) the request includes a description of the processing purpose for which the consumer's consent is sought and: (A) clearly distinguishes between an act or practice that is necessary to fulfill a request of the consumer and an act or practice that is for another purpose; (B) clearly states the specific categories of personal data that the controller intends to collect, process, transfer, or sell under each act or practice; and (C) is written in easy-to-understand language and includes a prominent heading that would enable a reasonable consumer to identify and understand each act or practice; (iii) the request clearly explains the consumer's rights related to consent; (iv) the request is made in a manner reasonably accessible to and usable by consumers with disabilities; (v) the request is made prior to the controller's implementation of the act or practice; (vi) the request is made available to the consumer in each language in which the controller provides a product or service for which authorization is sought; (vii) the option to refuse to give consent is at least as prominent as the option to give consent and the option to refuse to give consent takes the same number of steps or fewer as the option to give consent; and (viii) affirmative consent to an act or practice is not inferred from the inaction of the consumer or the consumer's continued use of a service or product provided by the controller.Ch. 93M § 1; and (4) establish a nonexclusive list of data collection, processing, and transfer practices that constitute unfair or deceptive practices in trade or commerce.
Section 11 authorizes the attorney general to promulgate rules and regulations to implement the chapter, including technical de-identification standards, data security baselines, a dark patterns list, and a list of unfair or deceptive data practices. This is a delegation of authority, not an affirmative compliance obligation on regulated entities.
(a)–(b) A violation of this chapter shall constitute an unfair or deceptive trade practice for purposes of chapter 93A. Notwithstanding sections 9 and 11 of said chapter 93A, the attorney general shall have exclusive authority to bring a civil action against any controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 or processorProcessor"Processor" means a person who collects, processes, or transfers personal data on behalf of, and at the direction of, a controller or another processor, or a Federal, State, Tribal, or local government entity.Ch. 93M § 1 other than a controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 or processorProcessor"Processor" means a person who collects, processes, or transfers personal data on behalf of, and at the direction of, a controller or another processor, or a Federal, State, Tribal, or local government entity.Ch. 93M § 1 that is a large data holderLarge data holder"Large data holder" means a controller or processor that in the most recent calendar year: (i) had annual gross revenues of $200,000,000 or more; and (ii) collected, processed, or transferred the covered data of more than 2,000,000 consumers or devices that identify or are linked or reasonably linkable to one or more consumers, excluding covered data collected and processed solely for the purpose of initiating, rendering, billing for, finalizing, completing, or otherwise collecting payment for a requested product or service; or the sensitive covered data of more than 200,000 consumers or devices that identify or are linked or reasonably linkable to one or more consumers. The term "large data holder" does not include any instance in which the controller or processor would qualify as a large data holder solely on the basis of collecting or processing personal email addresses, personal telephone numbers, or log-in information of an individual or device to allow the individual or device to log in to an account administered by the controller or processor.Ch. 93M § 1 that violates this chapter or a regulation adopted under this chapter to: (1) enjoin an act or practice that is in violation of this chapter or a regulation adopted under this chapter, including an order that an entity retrieve any personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 transferred in such violation; (2) enforce compliance with this chapter or a regulation adopted under this chapter, including seeking declaratory relief; (3) obtain damages, including punitive damages, restitution of any money or property obtained directly or indirectly by any such violation, and disgorgement of any profits, assets, property, or data obtained directly or indirectly by any such violation on behalf of the residents of the commonwealth; (4) impose civil penalties in an amount not more than $5,000 per violation; (5) obtain investigative costs, reasonable attorney's fees and other litigation costs, including, but not limited to, expert fees, reasonably incurred; and (6) obtain any such other and further relief as the court may deem proper. (b) If the court finds that a defendant has engaged in flagrant, willful, and repeated violations of this chapter in an action brought by the attorney general pursuant to subsection (a) of this section, the court may issue an order to suspend or prohibit the defendant from operating in the commonwealth in addition to any other remedies under subsection (a) of this section.
(d)–(f) Any provision of a contract or agreement of any kind, including but not limited to a controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1's terms of service or a privacy policy that purports to waive or limit in any way an individual's rights under this chapter, including but not limited to any right to a remedy or means of enforcement, shall be deemed contrary to public policy and shall be void and unenforceable. (e) The attorney general shall create, maintain and monitor a mechanism for consumersConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 to report potential violations of this chapter. (f) The attorney general shall issue an annual report to the clerks of the house and senate, the speaker of the house, the senate president, and the house and senate chairs of the joint committee on advanced information technology, the Internet and cybersecurity in a manner consistent with the requirements of section 11 of chapter 12, provided, however, that such report shall only relate to the enforcement of this chapter and its regulations.
Section 12 establishes the enforcement framework. Violations constitute unfair or deceptive trade practices under chapter 93A. The attorney general has exclusive enforcement authority against non-large-data-holder controllers and processors, notwithstanding sections 9 and 11 of chapter 93A — effectively barring private actions against smaller entities. For large data holders, chapter 93A private remedies are preserved. The AG may obtain injunctive relief, damages (including punitive), restitution, disgorgement, civil penalties up to $5,000 per violation, and attorney's fees. For flagrant, willful, and repeated violations, the court may suspend or prohibit the defendant from operating in Massachusetts. Contractual waivers of consumer rights are void. The AG must maintain a consumer complaint mechanism and issue annual enforcement reports.
Nothing in this chapter shall diminish any individual's rights or obligations under any other chapter or under any regulations promulgated thereunder.
Section 13 is a savings clause preserving existing rights and obligations under other chapters and regulations. It creates no new compliance obligation.
(a)–(b) 15 With respect to precise geolocation dataPrecise geolocation data"Precise geolocation data" means information derived from technology, including, but not limited to, latitude and longitude coordinates from global positioning system mechanisms or other similar positional data, that reveals the past or present physical location of an individual or device that identifies or is linked or reasonably linkable to 1 or more individuals with precision and accuracy within a radius of 1,750 feet.Ch. 93M § 1 that reveals that an individual or a device that identifies or is linked or reasonably linkable to 1 or more individuals is presently or was previously in the Commonwealth of Massachusetts: (1) an individual shall have the same rights, privileges, and protections as a consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 under this chapter for all such precise geolocation dataPrecise geolocation data"Precise geolocation data" means information derived from technology, including, but not limited to, latitude and longitude coordinates from global positioning system mechanisms or other similar positional data, that reveals the past or present physical location of an individual or device that identifies or is linked or reasonably linkable to 1 or more individuals with precision and accuracy within a radius of 1,750 feet.Ch. 93M § 1; and (2) a controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 shall treat such precise geolocation dataPrecise geolocation data"Precise geolocation data" means information derived from technology, including, but not limited to, latitude and longitude coordinates from global positioning system mechanisms or other similar positional data, that reveals the past or present physical location of an individual or device that identifies or is linked or reasonably linkable to 1 or more individuals with precision and accuracy within a radius of 1,750 feet.Ch. 93M § 1 in the same manner as it would the precise geolocation data of a consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 under this chapter. (b) Subsection (a) does not apply to the extent that an individual is acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency, but only if the individual's precise geolocation dataPrecise geolocation data"Precise geolocation data" means information derived from technology, including, but not limited to, latitude and longitude coordinates from global positioning system mechanisms or other similar positional data, that reveals the past or present physical location of an individual or device that identifies or is linked or reasonably linkable to 1 or more individuals with precision and accuracy within a radius of 1,750 feet.Ch. 93M § 1 is collected, processed, or transferred solely in relation to that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.
Section 14 extends the chapter's precise geolocation data protections to non-residents whose location data reveals they are or were present in Massachusetts. Non-resident individuals receive the same rights as consumers for such geolocation data, and controllers must treat the data identically. The employee-context exemption applies.
(a)–(c) 16 A controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 may transfer personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 to a third party in the context of a merger, acquisition, bankruptcy or similar transaction when the third party assumes control, in whole or in part, of the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1's assets, only if the controllerController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1, in a reasonable time prior to the transfer, provides an affected consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 with: (1) notice describing the transfer, including the name of the entity receiving the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1's personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 and the applicable privacy policies of such entity; and (2) a reasonable opportunity to withdraw previously provided consent related to the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1's personal dataPersonal data"Personal data" means any information, including derived data and unique identifiers, that is linked or reasonably linkable, alone or in combination with other information, to an identified or identifiable individual or a device that identifies or is linked or reasonably linkable to an individual. "Personal data" does not include de-identified data or publicly available information.Ch. 93M § 1 or otherwise exercise the rights guaranteed by this chapter. (b) In any transaction involving the transfer of genetic, neural, or biometric dataBiometric data"Biometric data" means data generated by automatic measurements of an individual's biological characteristics, such as a fingerprint, a voiceprint, eye retinas, irises, gait, or other unique biological patterns or characteristics that can be used to identify a specific individual. "Biometric data" does not include: (i) a digital or physical photograph, (ii) an audio or video recording, or (iii) any data generated from a digital or physical photograph, or an audio or video recording, unless such data is generated to identify a specific individual.Ch. 93M § 1, the reasonable opportunity under paragraph (2) of subsection (a) shall be no shorter than 60 days. (c) Nothing in this section shall be construed to diminish the requirements of paragraph (6) of subsection (a) of section 6.
Section 15 requires controllers to provide affected consumers with notice and a reasonable opportunity to withdraw consent or exercise their rights before transferring personal data to a third party in a merger, acquisition, or bankruptcy. For transfers involving genetic, neural, or biometric data, the withdrawal window must be at least 60 days.
17 By January 1, 2027, a person shall not develop or maintain a browser that does not include a setting that enables a consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 to send an opt-out preference signal, as described in section 6(e)(2), to controllersController"Controller" means a person who, alone or jointly with others, determines the purpose and means of collecting or processing personal data.Ch. 93M § 1 or processorsProcessor"Processor" means a person who collects, processes, or transfers personal data on behalf of, and at the direction of, a controller or another processor, or a Federal, State, Tribal, or local government entity.Ch. 93M § 1 that the consumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 interacts with through the browser.
Section 16 imposes a standalone obligation on browser developers: by January 1, 2027, no person may develop or maintain a browser that does not include a setting enabling consumers to send an opt-out preference signal to controllers and processors. This is a product-design mandate directed at browser manufacturers, distinct from the controller-facing opt-out signal obligation in Section 6(e)(2).
SECTION 1 shall take effect 180 days after enactment.
Section 2 of the enacting bill provides that Chapter 93M takes effect 180 days after enactment. This is a timing provision, not an independent compliance obligation.
The first data protection assessments required by section 8 of the Massachusetts ConsumerConsumer"Consumer" means an individual who is a resident of this state. "Consumer" does not include an individual acting as an employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, nonprofit or government agency whose communications or transactions with the controller occur solely within the context of that individual's role with the company, partnership, sole proprietorship, nonprofit or government agency.Ch. 93M § 1 Data Privacy Act shall be completed no later than the first anniversary of the effective date of this Act.
Section 3 of the enacting bill sets a deadline for the first data protection assessments: they must be completed no later than one year after the effective date. This provision qualifies the Section 8 assessment obligation but does not create an independent compliance duty.