<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Massachusetts Amends Its Strict Data Privacy Law (Yet, Again)</title>
	<atom:link href="http://www.compliancebuilding.com/2009/11/05/massachusetts-amends-its-strict-data-privacy-law-yet-again/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.compliancebuilding.com/2009/11/05/massachusetts-amends-its-strict-data-privacy-law-yet-again/</link>
	<description>Doug Cornelius on compliance and business ethics for private equity real estate</description>
	<lastBuildDate>Mon, 13 Feb 2012 12:56:20 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Data Accountability and Trust Act Passed by House &#124; Compliance Building</title>
		<link>http://www.compliancebuilding.com/2009/11/05/massachusetts-amends-its-strict-data-privacy-law-yet-again/comment-page-1/#comment-11875</link>
		<dc:creator>Data Accountability and Trust Act Passed by House &#124; Compliance Building</dc:creator>
		<pubDate>Fri, 17 Dec 2010 12:54:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.compliancebuilding.com/?p=4834#comment-11875</guid>
		<description>[...] This bill would preempt any state laws in the area, wiping out the Massachusetts Data Privacy Law [Massachusetts Amends Its Strict Data Privacy Law (Yet, Again)]. [...]</description>
		<content:encoded><![CDATA[<p>[...] This bill would preempt any state laws in the area, wiping out the Massachusetts Data Privacy Law [Massachusetts Amends Its Strict Data Privacy Law (Yet, Again)]. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: National Data Privacy Laws Move Forward &#124; Compliance Building</title>
		<link>http://www.compliancebuilding.com/2009/11/05/massachusetts-amends-its-strict-data-privacy-law-yet-again/comment-page-1/#comment-10601</link>
		<dc:creator>National Data Privacy Laws Move Forward &#124; Compliance Building</dc:creator>
		<pubDate>Mon, 29 Nov 2010 18:32:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.compliancebuilding.com/?p=4834#comment-10601</guid>
		<description>[...] last week&#8217;s further revisions to the Massachusetts Data Privacy Law [Massachusetts Amends Its Strict Data Privacy Law (Yet, Again)], people are wondering if the federal government is going to step into the space and create a [...]</description>
		<content:encoded><![CDATA[<p>[...] last week&#8217;s further revisions to the Massachusetts Data Privacy Law [Massachusetts Amends Its Strict Data Privacy Law (Yet, Again)], people are wondering if the federal government is going to step into the space and create a [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stacy</title>
		<link>http://www.compliancebuilding.com/2009/11/05/massachusetts-amends-its-strict-data-privacy-law-yet-again/comment-page-1/#comment-5228</link>
		<dc:creator>Stacy</dc:creator>
		<pubDate>Tue, 23 Mar 2010 20:27:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.compliancebuilding.com/?p=4834#comment-5228</guid>
		<description>Hi.  Just wondering if this law went into effect on March 1, 2010 or if it was extended again.

Thanks.</description>
		<content:encoded><![CDATA[<p>Hi.  Just wondering if this law went into effect on March 1, 2010 or if it was extended again.</p>
<p>Thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Doug Cornelius</title>
		<link>http://www.compliancebuilding.com/2009/11/05/massachusetts-amends-its-strict-data-privacy-law-yet-again/comment-page-1/#comment-4713</link>
		<dc:creator>Doug Cornelius</dc:creator>
		<pubDate>Thu, 18 Feb 2010 17:09:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.compliancebuilding.com/?p=4834#comment-4713</guid>
		<description>We are starting to see a patchwork of state laws. So far, not seem incompatible. Since Mass. is the most detailed and the strictest most companies seem to be treating it as the standard.

Other states with data privacy laws include:

Nevada: http://www.compliancebuilding.com/2008/10/29/nevada-law-on-privacy-of-personal-information/
New Hampshire: http://www.compliancebuilding.com/2010/01/15/compliance-bits-and-pieces-for-january-15/
New York: http://www.compliancebuilding.com/2008/12/10/six-states-now-require-social-security-nu/
New Mexico: http://www.compliancebuilding.com/2008/12/10/six-states-now-require-social-security-nu/
Michigan: http://www.compliancebuilding.com/2008/12/10/six-states-now-require-social-security-nu/
Texas: http://www.compliancebuilding.com/2008/12/10/six-states-now-require-social-security-nu/</description>
		<content:encoded><![CDATA[<p>We are starting to see a patchwork of state laws. So far, not seem incompatible. Since Mass. is the most detailed and the strictest most companies seem to be treating it as the standard.</p>
<p>Other states with data privacy laws include:</p>
<p>Nevada: <a href="http://www.compliancebuilding.com/2008/10/29/nevada-law-on-privacy-of-personal-information/" rel="nofollow">http://www.compliancebuilding.com/2008/10/29/nevada-law-on-privacy-of-personal-information/</a><br />
New Hampshire: <a href="http://www.compliancebuilding.com/2010/01/15/compliance-bits-and-pieces-for-january-15/" rel="nofollow">http://www.compliancebuilding.com/2010/01/15/compliance-bits-and-pieces-for-january-15/</a><br />
New York: <a href="http://www.compliancebuilding.com/2008/12/10/six-states-now-require-social-security-nu/" rel="nofollow">http://www.compliancebuilding.com/2008/12/10/six-states-now-require-social-security-nu/</a><br />
New Mexico: <a href="http://www.compliancebuilding.com/2008/12/10/six-states-now-require-social-security-nu/" rel="nofollow">http://www.compliancebuilding.com/2008/12/10/six-states-now-require-social-security-nu/</a><br />
Michigan: <a href="http://www.compliancebuilding.com/2008/12/10/six-states-now-require-social-security-nu/" rel="nofollow">http://www.compliancebuilding.com/2008/12/10/six-states-now-require-social-security-nu/</a><br />
Texas: <a href="http://www.compliancebuilding.com/2008/12/10/six-states-now-require-social-security-nu/" rel="nofollow">http://www.compliancebuilding.com/2008/12/10/six-states-now-require-social-security-nu/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://www.compliancebuilding.com/2009/11/05/massachusetts-amends-its-strict-data-privacy-law-yet-again/comment-page-1/#comment-4691</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Tue, 16 Feb 2010 18:51:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.compliancebuilding.com/?p=4834#comment-4691</guid>
		<description>Are other states following MA&#039;s lead?  If so, how do I find out which states?</description>
		<content:encoded><![CDATA[<p>Are other states following MA&#8217;s lead?  If so, how do I find out which states?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Massachusetts Amends Strict Data Privacy Law (Again) &#124; Compliance Building</title>
		<link>http://www.compliancebuilding.com/2009/11/05/massachusetts-amends-its-strict-data-privacy-law-yet-again/comment-page-1/#comment-4514</link>
		<dc:creator>Massachusetts Amends Strict Data Privacy Law (Again) &#124; Compliance Building</dc:creator>
		<pubDate>Wed, 03 Feb 2010 21:01:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.compliancebuilding.com/?p=4834#comment-4514</guid>
		<description>[...] UPDATE: Another revision was published on November 5, 2009. See: Massachusetts Amends Its Strict Data Privacy Law (Yet, Again) [...]</description>
		<content:encoded><![CDATA[<p>[...] UPDATE: Another revision was published on November 5, 2009. See: Massachusetts Amends Its Strict Data Privacy Law (Yet, Again) [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: JParent</title>
		<link>http://www.compliancebuilding.com/2009/11/05/massachusetts-amends-its-strict-data-privacy-law-yet-again/comment-page-1/#comment-3634</link>
		<dc:creator>JParent</dc:creator>
		<pubDate>Fri, 18 Dec 2009 15:51:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.compliancebuilding.com/?p=4834#comment-3634</guid>
		<description>Thank you.</description>
		<content:encoded><![CDATA[<p>Thank you.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Doug Cornelius</title>
		<link>http://www.compliancebuilding.com/2009/11/05/massachusetts-amends-its-strict-data-privacy-law-yet-again/comment-page-1/#comment-3633</link>
		<dc:creator>Doug Cornelius</dc:creator>
		<pubDate>Fri, 18 Dec 2009 15:46:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.compliancebuilding.com/?p=4834#comment-3633</guid>
		<description>Absolutely! 

If you have a Massachusetts client&#039;s name and their social security number, then you are subject to this law.  If you get a W-9 or tax filings or other filings through email and those filings have a Massachusetts client&#039;s name and their social security number, then that means your laptop and blackberry need to be encrypted. Your document systems need to be secure and you need proper protocols in place.</description>
		<content:encoded><![CDATA[<p>Absolutely! </p>
<p>If you have a Massachusetts client&#8217;s name and their social security number, then you are subject to this law.  If you get a W-9 or tax filings or other filings through email and those filings have a Massachusetts client&#8217;s name and their social security number, then that means your laptop and blackberry need to be encrypted. Your document systems need to be secure and you need proper protocols in place.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: JParent</title>
		<link>http://www.compliancebuilding.com/2009/11/05/massachusetts-amends-its-strict-data-privacy-law-yet-again/comment-page-1/#comment-3632</link>
		<dc:creator>JParent</dc:creator>
		<pubDate>Fri, 18 Dec 2009 15:34:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.compliancebuilding.com/?p=4834#comment-3632</guid>
		<description>Does it apply to law firms?</description>
		<content:encoded><![CDATA[<p>Does it apply to law firms?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Doug Cornelius</title>
		<link>http://www.compliancebuilding.com/2009/11/05/massachusetts-amends-its-strict-data-privacy-law-yet-again/comment-page-1/#comment-3293</link>
		<dc:creator>Doug Cornelius</dc:creator>
		<pubDate>Mon, 07 Dec 2009 19:02:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.compliancebuilding.com/?p=4834#comment-3293</guid>
		<description>The definition of &quot;personal information&quot; is the key to your question. Facebook clearly collects lots of personal information, but not the &quot;Personal Information&quot; defined under Massachusetts law:

Personal information, a Massachusetts resident&#039;s first name and last name or first initial and last name in combination with any one or more of the following data elements that relate to such resident: (a) Social Security number; (b) driver&#039;s license number or state-issued identification card number; or (c) financial account number, or credit or debit card number, with or without any required security code, access code, personal identification number or password, that would permit access to a resident’s financial account; provided, however, that “Personal information” shall not include information that is lawfully obtained from publicly available information, or from federal, state or local government records lawfully made available to the general public.

Since Facebook does not collect SSNs or financial account info, I don&#039;t think the kind of breach you mention is covered under the law.</description>
		<content:encoded><![CDATA[<p>The definition of &#8220;personal information&#8221; is the key to your question. Facebook clearly collects lots of personal information, but not the &#8220;Personal Information&#8221; defined under Massachusetts law:</p>
<p>Personal information, a Massachusetts resident&#8217;s first name and last name or first initial and last name in combination with any one or more of the following data elements that relate to such resident: (a) Social Security number; (b) driver&#8217;s license number or state-issued identification card number; or (c) financial account number, or credit or debit card number, with or without any required security code, access code, personal identification number or password, that would permit access to a resident’s financial account; provided, however, that “Personal information” shall not include information that is lawfully obtained from publicly available information, or from federal, state or local government records lawfully made available to the general public.</p>
<p>Since Facebook does not collect SSNs or financial account info, I don&#8217;t think the kind of breach you mention is covered under the law.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

