|
|
Like this article? PLEASE +1 it! |
|
Deadline Approaching for Mass Data Security Law: No More Time to Procrastinate
|
| Guest post by: Kenneth C. Halkin |
Article Overview: The March 1, 2010 deadline for compliance with the Massachusetts Data security Laws is fast approaching and will not likely be further extended. This law effects any business or individual who stores data on any Massachusetts resident whose unauthorized access might compromise the privacy of that individual’s personal information. Failure to comply could be costly. Compliance for some may be very simple, while for others it could be both complicate and expensive.
![]() |
Free Download - Financial Literacy for Business Owners & CEO’s: Do You Know & Understand Your Numbers? By Kenneth C. Halkin |
Deadline Approaching for Mass Data Security Law: No More Time to Procrastinate
The March 1, 2010 deadline for compliance with the
Massachusetts Data security Laws is fast approaching and will not likely be
further extended. This law effects any
business or individual who stores data on any Massachusetts resident whose unauthorized
access might compromise the privacy of that individual’s personal
information. Failure to comply could be
costly. Compliance for some may be very
simple, while for others it could be both complicate and expensive.
Personal information (PI) is defined as first name and last
name or first initial and last name along with one or more of the following:
- Social Security Number
- Drivers License number or state-issued card I.D. number
- Any financial account, debit or credit card number
If you have employees or independent contractors, then you are likely storing such personal information and must comply with the regulations under this law. If you take credit card information or bank account information from customers, and you store and/or transmit this information, then you must comply, as well. This data may be electronic or on paper. Both must be equally safeguarded.
Compliance involves the following:
- Employing safeguards for the secure storage, transmission and destruction of PI.
- Documenting those safeguards in the form of written policies and procedures.
- Providing documented training to employees and/or subcontractors who handle PI.
- Reporting known data security breaches to the individual, as well as to the required state authorities, including the Attorney General, Director of Consumer Affairs, Information Technology Division and Division of Public records.
The security of paper records involves limiting physical access to such files to those who have a business reason and are authorized to access and view the information. It further requires that such files be maintained in locked file cabinets or storage units when not being utilized. Even when in use, the information can not be visible to the public or to unauthorized personnel.
Electronic PI data must be password secured so that only authorized individuals can access it. If it transmitted through the internet or otherwise through phone lines or is stored on portable devices, such as flash drives or disks, the data must be encrypted so that it can not be read by unauthorized parties.
If you transmit data to subcontractors or vendors, such as Bookkeepers, Accountants or payroll services, you are responsible to assure that those entities are in full compliance with the law, as well.
The law also provides for the proper disposal of records, both physical and electronic, so that they can not be found and read by unauthorized parties. Te proper disposal of records must be documented. Those using third partied to destroy records must receive written documentation from the third party that the disposal was in compliance with the law.
Those found to be in non-compliance may be fined $5,000 for each violation plus assessed reasonable costs for investigation and litigation, including attorneys fees. It would not be surprising if after March 1, 2010, the AG’s Office goes looking for some test cases to try.
Related Articles
Home
> Management
> Kenneth C. Halkin
> Deadline Approaching for Mass Data Security Law No More Time to Procrastinate
> Google +
Article Tags:
Business Advice,
Business News,
Massachusetts data security,
Massachusetts security law Deadline
|
About the Author: Kenneth C. Halkin RSS for Kenneth's articles - Visit Kenneth's website Ken Halkin graduated from the SUNY at Stony Brook and received an MBA from Cornell University’s Graduate School of Business. Ken has served as a CAO, CFO, COO and CEO in a variety of organizations for a combined 27 years of consulting and executive level management experience in the public and private sectors. He has been responsible for major financial turnarounds, both as a consultant and as a CEO, and has assisted organizations in growing by as much as 800%. Ken has taught seminars, workshops and other professional development courses on: Financial Management; Budget Development and Management; Project Management; Time Management; Labor Relations; Human Resources Policy Development and Implementation; Employee Performance Evaluation; Exit and Succession Planning; and Strategic Planning. Coming from a family background of small business owners, Ken maintains a sincere interest in the success of small businesses. As an Accredited Executive Associate of the Institute for Independent Business (IIB), Ken is part of a worldwide network of nearly 4,000 senior business executives who commit their expertise to advising small and medium size business enterprises. Click here to visit Kenneth's website A Time To Consider Strategic Alliances Business Partnerships Hope for the Best and Prepare for the Worst Lost Your Job Thinking of Going Into Business for Yourself If You Do itDo it Right Planning Your Exit A Penny Saved is a Penny Earned 10 Easy Ways to Save on Business Expenses |
Related Forum Posts
Share this article with your friends. Fund someone's dream.
Leave a comment below or share on the left and you'll help support entrepreneurs in Africa through our partnership with Kiva. Over $50,000 raised and counting - Please keep sharing! Learn more.
Featured Article
Newsletter
Get advice & tips from famous business
owners, new articles by entrepreneur
experts, my latest website updates, &
special sneak peaks at what's to come!
Get advice & tips from famous business
owners, new articles by entrepreneur
experts, my latest website updates, &
special sneak peaks at what's to come!
Suggestions
Email us your ideas on how to make our
website more valuable! Thank you Sharon
from Toronto Salsa Lessons / Classes for
your suggestions to make the newsletter
look like the website and profile younger
entrepreneurs like Jennifer Lopez.
Email us your ideas on how to make our
website more valuable! Thank you Sharon
from Toronto Salsa Lessons / Classes for
your suggestions to make the newsletter
look like the website and profile younger
entrepreneurs like Jennifer Lopez.



