Recent Bills
- H.R. 10171August 27, 2026
- H.R. 10156August 27, 2026
- H.R. 10172August 27, 2026
- H.R. 10160August 27, 2026
- H.R. 10181August 27, 2026
- H.R. 10176August 27, 2026
- H.Res. 1496August 27, 2026
- H.R. 10164August 27, 2026
- H.R. 10170August 27, 2026
- H.Res. 1494August 27, 2026
- H.R. 10163August 27, 2026
- H.R. 10157August 27, 2026
Committees
- AdministrationU.S. House
- AgricultureU.S. House
- Agriculture, Nutrition, And ForestryU.S. House
- AppropriationsU.S. House
- Armed ServicesU.S. House
- Banking, Housing, And Urban AffairsU.S. House
- BudgetU.S. House
- Commerce, Science, And TransportationU.S. House
- Education and WorkforceU.S. House
- Energy And CommerceU.S. House
- Energy And Natural ResourcesU.S. House
- Environment And Public WorksU.S. House
- EthicsU.S. House
- FinanceU.S. House
- Financial ServicesU.S. House
- Foreign AffairsU.S. House
- Foreign RelationsU.S. House
- Health, Education, Labor, And PensionsU.S. House
- Homeland SecurityU.S. House
- Homeland Security And Governmental Affa…U.S. House
- Indian AffairsU.S. House
- Indian and Insular AffairsU.S. House
- IntelligenceU.S. House
- JudiciaryU.S. House
- Natural ResourcesU.S. House
- Oversight And Government ReformU.S. House
- Permanent Select IntelligenceU.S. House
- RulesU.S. House
- Rules And AdministrationU.S. House
- Science, Space, And TechnologyU.S. House
- Select IntelligenceU.S. Senate
- Small BusinessU.S. House
- Small Business And EntrepreneurshipU.S. House
- Subcommittee on AviationU.S. House
- Subcommittee on Border Security and Enf…U.S. House
- Subcommittee on Coast Guard and Maritim…U.S. House
- Subcommittee on Commodity Markets, Digi…U.S. House
- Subcommittee on Conservation, Research,…U.S. House
- Subcommittee on Counterterrorism and In…U.S. House
- Subcommittee on Cybersecurity and Infra…U.S. House
- Subcommittee on Disability Assistance a…U.S. House
- Subcommittee on Economic Development, P…U.S. House
- Subcommittee on Economic OpportunityU.S. House
- Subcommittee on Emergency Management an…U.S. House
- Subcommittee on Energy and Mineral Reso…U.S. House
- Subcommittee on Federal LandsU.S. House
- Subcommittee on Forestry and Horticultu…U.S. House
- Subcommittee on General Farm Commoditie…U.S. House
- Subcommittee on HealthU.S. House
- Subcommittee on Highways and TransitU.S. House
- Subcommittee on Livestock, Dairy, and P…U.S. House
- Subcommittee on Nutrition and Foreign A…U.S. House
- Subcommittee on Oversight and Investiga…U.S. House
- Subcommittee on Oversight, Investigatio…U.S. House
- Subcommittee on Railroads, Pipelines, a…U.S. House
- Subcommittee on Transportation and Mari…U.S. House
- Subcommittee on Water Resources and Env…U.S. House
- Subcommittee on Water, Wildlife and Fis…U.S. House
- Transportation And InfrastructureU.S. House
- Veterans' AffairsU.S. House
- Ways And MeansU.S. House

H 5472
Massachusetts House•Introduced
Summary
H 5472, “Site Information & Links”, was introduced in the House on Jun 4, 2026 by Rep. House Committee on Ways and Means. It last saw action on Jun 4, 2026: Published as amended, see H5479.
Record
Text
H 5472 has no co-sponsors and has not gone to a roll call.
h5472/introduced.txtHOUSE . . . . . . . No. 5472The Commonwealth of Massachusetts______________________________________HOUSE OF REPRESENTATIVES, June 3, 2026.The committee on Ways and Means, to whom was referred the SenateBill establishing the Massachusetts data privacy act (Senate, No. 2619)reports recommending that the same ought to pass with amendmentsstriking out all after the enacting clause and inserting in place thereof thetext contained in House document numbered 5472; by striking out the titleand inserting in place thereof the following title: “An Act establishing theMassachusetts consumer data privacy act.”.For the committee,AARON MICHLEWITZ.HOUSE . . . . . . . . . . . . . . . No. 5472The Commonwealth of Massachusetts_______________In the One Hundred and Ninety-Fourth General Court(2025-2026)_______________By striking out all after the enacting clause and inserting in place thereof the following:–1SECTION 1. The General Laws are hereby amended by inserting after chapter 93L the2 following chapter:-3Chapter 93M4Consumer Data Privacy5Section 1. As used in this chapter, the following words shall, unless the context clearly6 requires otherwise, have the following meanings:7“Affiliate”, a legal entity that shares common branding with another legal entity or that8 controls, is controlled by or is under common control with another legal entity. For the purposes9 of this definition, “control” and “controlled” shall mean:10(i) ownership of, or the power to vote, more than 50 per cent of the outstanding shares of11 any class of voting security of a company;12(ii) control in any manner over the election of a majority of the directors or of individuals13 exercising similar functions; or1 of 3814(iii) the power to exercise controlling influence over the management of a company.15“Affirmative consent”, a clear affirmative act signifying a consumer’s freely given,16 specific, informed and unambiguous agreement, including authorization for an act or practice;17 provided, that “affirmative consent” may include a written statement, including by electronic18 means, or any other unambiguous affirmative action; and provided further, that “affirmative19 consent” shall not include: (i) acceptance of general or broad terms of use or a similar document20 that contains descriptions of personal data processing along with other, unrelated information;21 (ii) hovering over, muting, pausing or closing a given piece of content; (iii) agreement obtained22 through the use of a false, fraudulent or materially misleading statement or representation; or (iv)23 agreement obtained through the use of dark patterns.24“Authenticate”, to use reasonable means to determine that a request to exercise any of the25 rights afforded under this chapter is being made by, or on behalf of, the consumer who is entitled26 to exercise such consumer rights with respect to the personal data at issue.27“Biometric data”, data generated by automatic measurements of an individual’s28 biological characteristics, including: (i) a fingerprint; (ii) a voiceprint; (iii) eye retinas; (iv) irises;29 (v) gait; or (vi) other unique biological patterns or characteristics that can be used to identify a30 specific individual; provided, however, that “biometric data” shall not include: (A) a digital or31 physical photograph; (B) an audio or video recording; or (C) any data generated from a digital or32 physical photograph or an audio or video recording, unless such data is generated to identify a33 specific individual.34“Business associate”, as defined in the Health Insurance Portability and Accountability35 Act of 1996, 42 U.S.C. 1320d et seq.2 of 3836“Child”, as defined in the Children’s Online Privacy Protection Act of 1998, 15 U.S.C.37 6501 et seq.38“Collect”, buying, renting, gathering, obtaining, receiving, accessing or otherwise39 acquiring personal data by any means.40“Consumer”, an individual who is a resident of the commonwealth; provided, however,41 that “consumer” shall not include an individual acting in a commercial or employment context or42 as an employee, owner, director, officer or contractor of a company, corporation, partnership,43 sole proprietorship, nonprofit organization or government agency whose communications or44 transactions with the controller occur solely within the context of that individual’s role with the45 company, corporation, partnership, sole proprietorship, nonprofit organization or government46 agency.47“Consumer health and wellness data”, personal data that is collected in real time or48 retroactively by a health and wellness device or application, which is designed to allow a49 consumer to track or monitor information regarding the consumer’s health and wellness,50 including, but not limited to: (i) fitness; (ii) nutrition; (iii) diet; (iv) physical activity; (v) sleep;51 (vi) mental state; (vii) stress; or (viii) behavior. “Consumer health and wellness data” shall not52 include biometric data, neural data, genetic data or personal data that reveals a mental or physical53 health condition, diagnosis, disability or treatment.54“Controller”, a person who, alone or jointly with others, determines the purpose and55 means of collecting or processing personal data.3 of 3856“COPPA”, the Children’s Online Privacy Protection Act of 1998, 15 U.S.C. 6501 et seq.,57 and the regulations, rules, guidance and exemptions adopted thereunder, as said act and58 regulations, rules, guidance and exemptions may be amended from time to time.59“Covered entity”, as defined in the Health Insurance Portability and Accountability Act60 of 1996, 42 U.S.C. 1320d et seq.61“Dark pattern”, a user interface designed or manipulated with the substantial effect of62 subverting or impairing user autonomy, decision-making or choice; provided, that “dark pattern”63 shall include, but shall not be limited to, any practice the Federal Trade Commission refers to as64 a “dark pattern”.65“Decisions that produce legal or similarly significant effects concerning the consumer”,66 any decision made by the controller, or on behalf of the controller, that result in the provision of,67 or denial by, the controller of any: (i) financial or lending services; (ii) housing; (iii) insurance;68 (iv) education enrollment or opportunity; (v) criminal justice; (vi) employment opportunities;69 (vii) health care services; or (viii) access to essential goods or services.70“De-identified data”, data that does not identify and cannot reasonably be used to infer71 information about, or otherwise be linked to, an identified or identifiable individual, or a device72 linked to such individual, if the controller that possesses such data:73(i) takes reasonable physical, administrative and technical measures to ensure that such74 data cannot be associated with an individual or be used to re-identify any individual or device75 that identifies or is linked or reasonably linkable to an individual;4 of 3876(ii) publicly commits to process such data only in a de-identified fashion and not attempt77 to re-identify such data; and78(iii) contractually obligates any recipients of such data to satisfy the criteria set forth in79 clauses (i) and (ii).80“Gender-affirming health care services”, as defined in section 11I½ of chapter 12.81“Gender-affirming health care data”, any personal data concerning an effort made by an82 individual to seek, or an individual’s receipt of, gender-affirming health care services.83“Genetic data”, any data, regardless of its format, that concerns an individual’s genetic84 characteristics, including, but not limited to: (i) raw sequence data that results from the85 sequencing of the complete, or a portion of the, extracted deoxyribonucleic acid of an individual;86 and (ii) any genotypic and phenotypic information that results from analyzing such raw sequence87 data.88“HIPAA”, the Health Insurance Portability and Accountability Act of 1996, 42 U.S.C.89 1320d et seq., as amended from time to time.90“Identified or identifiable individual”, an individual who can be readily identified,91 directly or indirectly.92“Large data holder”, a controller or processor that in the most recent calendar year93 collected, processed or sold the: (i) personal data of more than 2,000,000 consumers; provided,94 however, that said personal data shall not include personal data collected and processed solely95 for the purpose of initiating, rendering, billing for, finalizing, completing or otherwise collecting5 of 3896 payment for a requested product or service; or (ii) sensitive data of more than 200,00097 consumers.98“Legally-protected health care activity”, as defined in section 11I½ of chapter 12.99“Legally-protected health care data”, any personal data concerning any effort made by a100 consumer to seek, or a consumer’s receipt of, legally-protected health care activity.101“Minor”, any individual who is younger than 18 years of age.102“Neural data”, any information that is generated by measuring the activity of an103 individual’s central or peripheral nervous system.104“Person”, an individual, association, company, limited liability company, corporation,105 partnership, sole proprietorship, trust or other legal entity.106“Personal data”, any information, including derived data, that is linked or reasonably107 linkable, alone or in combination with other information, to an identified or identifiable108 individual; provided, however, that “personal data” shall not include de-identified data or109 publicly available information.110“Precise geolocation data”, information derived from technology, including, but not111 limited to, latitude and longitude coordinates from global positioning system mechanisms or112 other similar positional data, that reveals the specific location of an individual or device that113 identifies or is linked or reasonably linkable to 1 or more individuals with precision and accuracy114 within a radius of 1,750 feet. “Precise geolocation data” shall not include the content of115 communications, a photograph or video, metadata associated with a photograph or video that6 of 38116 cannot be linked to an individual or any data generated by or connected to advanced utility117 metering infrastructure systems or equipment for use by a utility.118“Process”, any operation or set of operations performed, whether by manual or automated119 means, on personal data or on sets of personal data, including, but not limited to, the: (i) use; (ii)120 storage; (iii) disclosure; (iv) analysis; and (v) deletion or modification of personal data.121“Processor”, a person who collects or processes personal data on behalf of, or at the122 direction of: (i) a controller; (ii) another processor; or (iii) a federal, state, tribal or local123 government entity.124“Profiling”, any form of processing performed on personal data to evaluate, analyze or125 predict personal aspects, including, but not limited to, an individual’s: (i) economic situation; (ii)126 health; (iii) personal preferences; (iv) interests; (v) reliability; (vi) behavior; (vii) location; or127 (viii) movements.128“Protected health information”, as defined in the Health Insurance Portability and129 Accountability Act of 1996, 42 U.S.C. 1320d et seq.130“Publicly available information”, information that is lawfully made available to the131 general public from: (i) federal, state or municipal government records; (ii) widely distributed132 media; or (iii) a disclosure to the general public as required by federal, state or local law;133 provided, that a controller shall have a reasonable basis to believe that: (A) a consumer has134 lawfully made the information available to the general public; or (B) the information has been135 lawfully made available to the general public from widely distributed media. “Publicly available136 information” shall not include: (i) any obscene visual depiction, as defined in 18 U.S.C. 1460;137 (ii) any inference made exclusively from multiple independent sources of publicly available7 of 38138 information that reveals sensitive data with respect to a consumer; (iii) biometric data; (iv)139 genetic or neural data, unless otherwise made publicly available by the individual to whom the140 information pertains; (v) information made available by a consumer on a website or online141 service made available to all members of the public, for free or for a fee, where the consumer has142 restricted the information to a specific audience; or (vi) intimate images, authentic or computer-143 generated, known to be nonconsensual, including, but not limited to, images distributed in144 violation of section 43A of chapter 265.145“Reproductive or sexual health care”, any health care-related services or products146 rendered or provided concerning a consumer’s reproductive system or sexual well-being,147 including, but not limited to, reproductive health care services as defined in section 11I½ of148 chapter 12 or any such service or product rendered or provided concerning:149(i) an individual’s health condition, status, disease, diagnosis, diagnostic test or treatment;150(ii) a social, psychological, behavioral or medical intervention;151(iii) a surgery or procedure, including, but not limited to, an abortion;152(iv) a use or purchase of a medication, including, but not limited to, a medication used or153 purchased for the purposes of an abortion;154(v) a bodily function, vital sign or symptom;155(vi) a measurement of a bodily function, vital sign or symptom; or156(vii) an abortion, including, but not limited to, medical or nonmedical services, products,157 diagnostics, counseling or follow-up services for an abortion.8 of 38158“Reproductive or sexual health data”, any personal data concerning an effort made by a159 consumer to seek, or a consumer’s receipt of, reproductive or sexual health care.160“Sale of personal data”, the exchange, disclosure, release, dissemination, license or rental161 of personal data, or other means of making personal data available, for monetary or other162 valuable consideration by the controller to a third party. “Sale of personal data” shall not include:163(i) the disclosure of personal data to a processor that processes the personal data on164 behalf of the controller;165(ii) the disclosure of personal data to a third party for purposes of providing a product or166 service requested by the consumer;167(iii) the disclosure or sale of personal data to an affiliate of the controller;168(iv) with the consumer’s affirmative consent, the disclosure of personal data where the169 consumer affirmatively directs the controller to disclose the personal data or intentionally uses170 the controller to interact with a third party;171(v) the disclosure or sale of personal data to a third party as an asset that is part of a172 merger, acquisition, bankruptcy or other transaction or a proposed merger, acquisition,173 bankruptcy or other transaction, in which the third party assumes control of all or part of the174 controller’s assets; or175(vi) the disclosure or sale of personal data to a third party as part of a merger, acquisition,176 bankruptcy or similar transaction where the third party assumes control, in whole or in part, of177 the controller’s assets; provided, that the controller shall, in a reasonable time prior to the178 disclosure or transfer, provide an affected consumer with: (i) notice describing the transfer,9 of 38179 including, but not limited to: (A) the name of the entity receiving the consumer’s personal data;180 and (B) the applicable privacy policies of such entity; and (ii) a reasonable opportunity to181 withdraw affirmative consent related to the consumer’s personal data or otherwise exercise the182 rights guaranteed by this chapter; provided, that said reasonable opportunity shall be not less183 than 60 days if the sale is related to genetic data, neural data or biometric data; provided further,184 that nothing shall be construed to change the requirements of paragraph (3) of section 6.185“Sensitive data”, personal data that includes:186(i) data revealing a consumer’s: (A) racial or ethnic origin, color, national origin or187 citizenship or immigration status; (B) religious beliefs; (C) mental or physical health condition,188 diagnosis, disability or treatment, including, but not limited to, gender-affirming health data,189 reproductive or sexual health data or legally-protected health care data; (D) sex life, sexual190 orientation, status as transgender or non-binary; (E) union membership; (F) status as a victim of a191 crime; or (G) status as a military servicemember or veteran;192(ii) consumer health and wellness data;193(iii) genetic data194(iv) neural data;195(v) biometric data;196(vi) personal data of a consumer that a controller knows, or willfully disregards, is a197 minor;198(vii) precise geolocation data;10 of 38199(viii) a government-issued identifier, including a Social Security number, passport200 number or driver’s license number, that is not required by law to be displayed in public; or201(ix) account names, passwords, usernames that are not publicly available or that have a202 restricted audience, access codes, security questions or answers or other credentials and203 information used to log in to an account or device, including, but not limited to, passkeys.204“Targeted advertising”, displaying advertisements to a consumer where the advertisement205 is selected based on personal data obtained or inferred from that consumer’s activities over time206 and across nonaffiliated internet web sites or online applications to predict such consumer’s207 preferences or interests; provided, however, that “targeted advertising” shall not include:208(i) advertisements based on activities within a controller’s own websites or online209 applications;210(ii) advertisements based on the context of a consumer’s current search query, visit to a211 website or online application;212(iii) advertisements directed to a consumer in response to the consumer’s request for213 information or feedback; or214(iv) processing personal data solely to measure or report advertising frequency,215 performance or reach.216“Third party”, a person that collects personal data from another person that is not the217 consumer to whom the data pertains and is not a processor with respect to such data. “Third218 party” shall not include a person that collects personal data from another entity if the 2 entities219 are affiliates.11 of 38220“Trade secret”, as defined in section 42 of chapter 93.221Section 2. This chapter shall apply to persons that conduct business in the commonwealth222 and produce products or provide services that are targeted to residents of the commonwealth and223 that, during the preceding calendar year:224(i) collected or processed the personal data of not less than 100,000 consumers; provided,225 however, that said personal data shall not include personal data controlled or processed solely for226 the purpose of completing a payment transaction;227(ii) derived gross revenue of not less than $100,000 from the sale of personal data; or228(iii) collected or processed sensitive data; provided, however, that sensitive data shall not229 include personal data controlled or processed solely for the purpose of completing a payment230 transaction.231Section 3. (a) This chapter shall not apply to:232(1) any federal, state, tribal, territorial or local government entity such as a body,233 authority, board, bureau, commission, district or agency of the commonwealth or any political234 subdivision of the commonwealth;235(2) a nonprofit organization established to detect and prevent fraudulent acts in236 connection with insurance that is operating solely for that purpose;237(3) a national securities association registered pursuant to section 15A of the Securities238 Exchange Act of 1934 and the rules and implementing regulations promulgated thereunder;12 of 38239(4) a registered futures association designated pursuant to section 17 of the Commodity240 Exchange Act and the rules and implementing regulations promulgated thereunder;241(5) a bank, credit union or any affiliate or subsidiary thereof that: (A) is only and directly242 engaged in financial activities as described in 12 U.S.C. 1843(k); (B) is regulated and examined243 by the division of banks or an applicable federal bank regulatory agency; and (C) has established244 a program to comply with all applicable requirements established by the commissioner of banks245 or the applicable federal bank regulatory agency concerning personal data;246(6) an educational nonprofit organization, including an institution of higher education;247(7) a nonprofit organization that establishes or maintains a blood bank or transfusion248 service pursuant to section 184B of chapter 111 and in compliance with applicable requirements249 of the U.S. Food and Drug Administration, including, but not limited to, 21 C.F.R. parts 600,250 601, 606, 607, 610, 630 and 640, as amended, and any successor provisions; or251(8) an agent, broker-dealer, investment adviser or investment adviser representative, as252 defined in section 401 of chapter 110A, who is regulated by the secretary of the commonwealth253 or the United States Securities and Exchange Commission.254(b) Notwithstanding subsection (a), any entity exempt pursuant to subsection (a) shall255 comply with clause (i) of subsection (a) of section 7.256(c) The following information and data shall be exempt from this chapter:257(1) protected health information that a covered entity or business associate collects or258 processes in accordance with or documents that a covered entity or business associate creates for13 of 38259 the purpose of complying with HIPAA and regulations promulgated under HIPAA, as in effect260 on the effective date of this chapter;261(2) patient-identifying information for purposes of 42 U.S.C. 290dd-2;262(3) identifiable private information for purposes of the federal policy for the protection of263 human subjects under 45 C.F.R. 46;264(4) identifiable private information that is otherwise information collected as part of265 human subjects research pursuant to the good clinical practice guidelines issued by the266 International Council for Harmonisation of Technical Requirements for Pharmaceuticals for267 Human Use;268(5) the protection of human subjects under 21 C.F.R. parts 50 and 56, or personal data269 used or shared in research, as defined in 45 C.F.R. 164.501, that is conducted in accordance with270 the standards set forth in this paragraph and paragraphs (3) and (4), or other research conducted271 in accordance with applicable law;272(6) information and documents created for purposes of the Health Care Quality273 Improvement Act of 1986, 42 U.S.C. 11101 et seq.;274(7) patient safety work product for purposes of the Patient Safety and Quality275 Improvement Act of 2005, 42 U.S.C. 299b-21 et seq., as amended from time to time;276(8) information derived from any of the health care-related information listed in this277 subsection that is de-identified in accordance with the requirements for de-identification pursuant278 to HIPAA;14 of 38279(9) personal information collected, processed or sold subject to Title V of the Gramm-280 Leach-Bliley Act, 15 U.S.C. 6801 et seq.;281(10) the collection, maintenance, disclosure, sale, communication or use of any personal282 information bearing on a consumer’s credit worthiness, credit standing, credit capacity,283 character, general reputation, personal characteristics or mode of living by a consumer reporting284 agency, furnisher or user that provides information for use in a consumer report, and by a user of285 a consumer report, but only to the extent that such activity is regulated by and authorized under286 the Fair Credit Reporting Act, 15 U.S.C. 1681 et seq., as amended from time to time;287(11) personal data collected, processed, sold or disclosed in compliance with the Driver’s288 Privacy Protection Act of 1994, 18 U.S.C. 2721 et seq., as amended from time to time;289(12) personal data regulated by the Family Educational Rights and Privacy Act, 20290 U.S.C. 1232g et seq., as amended from time to time;291(13) personal data collected, processed, sold or disclosed in compliance with the Farm292 Credit Act, 12 U.S.C. 2001 et seq., as amended from time to time;293(14) data collected or processed: (i) in the course of an individual applying to, employed294 by or acting as an agent or independent contractor of a controller, processor or third party, to the295 extent that the data is collected and used within the context of that role; (ii) as the emergency296 contact information of an individual under this chapter used for emergency contact purposes; or297 (iii) that is necessary to retain to administer benefits for another individual relating to the298 individual who is the subject of the information under paragraph (1) and used for the purposes of299 administering such benefits; and15 of 38300(15) personal data collected, processed, sold or disclosed in relation to price, route or301 service, as such terms are used in the Federal Aviation Act of 1958, 49 U.S.C. 40101 et seq., to302 the extent this chapter is preempted by the Federal Aviation Act of 1958, and the Airline303 Deregulation Act of 1978, 49 U.S.C. 41713, as said acts may be amended from time to time.304(d) Controllers and processors that comply with the verifiable parental consent305 requirements of COPPA shall be deemed compliant with any obligation to obtain parental306 consent pursuant to this chapter.307Section 4. (a) A consumer shall have the right to:308(1) confirm whether a controller is collecting or processing the consumer’s personal data309 and access such personal data, including, but not limited to, any inferences about the consumer310 derived from such personal data; provided, however, that such confirmation or access shall not311 require the controller to reveal a trade secret;312(2) obtain from a controller a list of third parties, other than natural persons, to which the313 controller has sold either: (i) the consumer’s personal data; or (ii) any personal data; provided,314 however, that such confirmation or access shall not require the controller to reveal a trade secret;315(3) correct inaccuracies in the consumer’s personal data, taking into account the nature of316 the personal data and the purposes of the processing of the consumer’s personal data;317(4) delete personal data provided by, or obtained about, the consumer, including personal318 data the consumer provided to the controller, personal data the controller obtained from another319 source and derived data;16 of 38320(5) obtain a copy of the consumer’s personal data collected or processed by the321 controller, in a portable and, to the extent technically feasible, readily usable format that allows322 the consumer to transmit the data to another controller without hindrance, where the processing323 is carried out by automated means; and324(6) opt out of the collection and processing of the consumer’s personal data for purposes325 of: (i) targeted advertising; (ii) the sale of personal data; or (iii) profiling in furtherance of solely326 automated decisions that produce legal or similarly significant effects concerning the consumer.327(b) A consumer may exercise rights under this section by a secure and reliable means328 established by the controller and described to the consumer in the controller’s privacy notice329 pursuant to section 8. A consumer may designate an authorized agent in accordance with section330 5 to exercise the rights of such consumer specified in this section on behalf of the consumer.331(c) Except as otherwise provided in this chapter, a controller shall comply with a request332 by a consumer to exercise the consumer rights authorized pursuant to this section as follows:333(1) A controller shall respond to the consumer without undue delay, but not later than 45334 days after receipt of the request. The controller may extend the response period by 45 additional335 days when reasonably necessary, considering the complexity and number of the consumer’s336 requests; provided, that the controller shall inform the consumer of any such extension and the337 reason for the extension within the initial 45-day response period.338(2) If a controller declines to take action regarding the consumer’s request, the controller339 shall inform the consumer without undue delay, but not later than 45 days after receipt of the340 request, of the justification for declining to take action and instructions for how to appeal the341 decision.17 of 38342(3) Information provided in response to a consumer request shall be provided by a343 controller, free of charge, not less than twice per consumer during any 12-month period. If344 requests from a consumer are manifestly unfounded, excessive or repetitive, the controller may345 charge the consumer a reasonable fee to cover the administrative costs of complying with the346 request or decline to act on the request. The controller shall bear the burden of demonstrating347 that a request is manifestly unfounded, excessive or repetitive.348(4) If a controller is unable to authenticate a request to exercise any of the rights afforded349 under paragraphs (1) to (5), inclusive, of subsection (a) using commercially reasonable efforts,350 the controller shall not be required to comply with a request to initiate an action pursuant to this351 section and shall provide notice to the consumer that the controller is unable to authenticate the352 request to exercise such right until such consumer provides additional information reasonably353 necessary to authenticate such consumer and such consumer’s request to exercise such right;354 provided, that any such information shall not be used for any purpose other than the355 authentication of the consumer. A controller shall not require authentication to exercise an opt-356 out request, but a controller may deny an opt-out request if the controller has a good faith,357 reasonable and documented belief that the request is fraudulent. If a controller denies an opt-out358 request because the controller believes such request is fraudulent, the controller shall send a359 notice to the person who made such request disclosing that the controller believes the request is360 fraudulent, why such controller believes the request is fraudulent and that the controller shall not361 comply with the request.362(5) A controller that has obtained personal data about a consumer from a source other363 than the consumer shall be deemed in compliance with a consumer’s request to delete such364 personal data pursuant to paragraph (4) of subsection (a) by deleting the consumer’s personal18 of 38365 data retained by the controller and retaining a record of the deletion request and the minimum366 data necessary for the purpose of ensuring the consumer’s personal data remains deleted from the367 controller’s records and not using such retained data for any other purpose pursuant to this368 chapter.369(d) A controller shall establish a process for a consumer to appeal the controller’s refusal370 to take action on a request within a reasonable period of time after the consumer’s receipt of the371 decision. The appeal process shall be conspicuously available and similar to the process for372 submitting requests to initiate action pursuant to subsection (b). Not later than 60 days after373 receipt of an appeal, a controller shall inform the consumer in writing of any action taken or not374 taken in response to the appeal, including a written explanation of the reasons for the decision. If375 the appeal is denied, the controller shall provide the consumer with an online mechanism, if376 available, or other method, including mail or in person, through which the consumer may contact377 the attorney general to submit a complaint.378(e) A controller shall not condition, effectively condition, attempt to condition or attempt379 to effectively condition the exercise of a right described in this section through the use of: (i) any380 false, fictitious, fraudulent or materially misleading statement or representation; or (ii) dark381 patterns.382(f) A controller or processor shall not collect or process personal data in a manner that383 unlawfully discriminates against an individual or class of individuals, threatens to discriminate384 against an individual or class of individuals or otherwise makes unavailable the equal enjoyment385 of goods or services on the basis of an individual’s or class of individuals’ actual or perceived386 race, color, sex, sexual orientation, gender identity, disability, religion, genetic information,19 of 38387 pregnancy or condition related to pregnancy, status as a veteran, ancestry, national origin,388 citizenship or immigration status or any other basis protected by chapter 151B.389(g) Subsection (f) shall not apply to:390(i) the collection or processing of personal data for the sole purpose of: (A) a controller or391 processor’s self-testing to prevent or mitigate unlawful discrimination or otherwise to ensure392 compliance with state or federal law; or (B) diversifying an applicant, participant or customer393 pool; or394(ii) a private establishment, as described in 42 U.S.C. 2000a(e).395Section 5. (a) A consumer may designate another person to serve as the consumer’s396 authorized agent to act on such consumer’s behalf to exercise rights specified in paragraph (6) of397 subsection (a) of section 4. A parent or legal guardian of a minor may exercise a consumer right398 under said subsection (a) of said section 4 on the minor’s behalf. For a consumer subject to a399 guardianship, conservatorship or other protective arrangement, the guardian or conservator of the400 consumer may exercise a consumer right under said subsection (a) of said section 4 on the401 consumer’s behalf.402(b) A controller shall comply with a request received from an authorized agent if the403 controller is able to authenticate, with commercially reasonable effort, the identity of the404 consumer and the authorized agent’s authority to act on such consumer’s behalf.405Section 6. A controller shall:406(1) limit the collection of personal data to what is reasonably necessary and proportionate407 in relation to the purposes for which the personal data is collected or processed, as disclosed to20 of 38408 the consumer; provided, that in determining what is reasonably necessary and proportionate the409 following shall be taken into account, the: (i) consumer’s reasonable expectation regarding the410 personal data at the time the personal data was collected based on the purposes that were411 disclosed to the consumer; (ii) relationship that the new purpose bears to the purposes that were412 disclosed to the consumer; (iii) impact that processing the personal data for the new purpose413 might have on the consumer; (iv) relationship between the consumer and the controller and the414 context in which the personal data were collected; and (v) existence of additional safeguards,415 including, but not limited to, encryption, in processing such personal data for such new purpose;416(2) unless the controller obtains the consumer’s affirmative consent, not process the417 consumer’s personal data for any materially new purpose that is neither reasonably necessary to,418 nor compatible with, the purposes that were disclosed to the consumer;419(3) not collect or process sensitive data concerning a consumer without obtaining the420 consumer’s affirmative consent, or, in the case of the processing of sensitive data concerning a421 known child, without processing such sensitive data in accordance with COPPA;422(4) establish, implement and maintain reasonable administrative, technical and physical423 data security practices to protect the confidentiality, integrity and accessibility of personal data424 appropriate to the volume and nature of the personal data at issue, including, but not limited to,425 disposing of personal data in accordance with a retention schedule that requires the deletion of426 personal data when the personal data is required to be deleted by law or is no longer necessary427 for the purpose for which the data was collected or processed; and428(5) provide an effective mechanism for a consumer to revoke the consumer’s affirmative429 consent that is at least as easy as the mechanism by which the consumer provided the consumer’s21 of 38430 affirmative consent and, upon revocation of such affirmative consent, cease to process the431 personal data as soon as practicable, but not later than 15 days after the receipt of such request.432Section 7. (a) A controller shall not:433(i) sell: (A) precise geolocation data of any individual or consumer collected or processed434 within the commonwealth, regardless of the residency of the individual or consumer; provided,435 that precise geolocation data shall not be sold even with the affirmative consent of an individual436 or consumer; or (B) sensitive data other than precise geolocation data without obtaining the437 consumer’s affirmative consent; and provided further, that in the case of the collection or438 processing of personal data concerning a known child, personal data shall be collected and439 processed in accordance with COPPA;440(ii) collect or process the personal data of a consumer for purposes of targeted advertising441 or sell the consumer’s personal data under circumstances where a controller has actual442 knowledge or willfully disregards that the consumer is a minor; or443(iii) discriminate or retaliate against a consumer, or threaten to discriminate or retaliate444 against a consumer, for exercising any of the consumer rights contained in this chapter, or for445 refusing to agree to the collection or processing of personal data for a specific product or service,446 including, but not limited to, denying goods or services, charging different prices or rates for447 goods or services or providing a different level of quality of goods or services to the consumer.448(b)(1) Nothing in paragraph (iii) of subsection (a) shall be construed to require a449 controller to provide a specific product or service that requires the personal data of a consumer450 which the controller does not collect or maintain, or prohibit a controller from offering a451 different price, rate, level, quality or selection of goods or services to a consumer, including22 of 38452 offering goods or services for no fee, if the offering is in connection with a consumer’s voluntary453 participation in a bona fide loyalty, rewards, premium features, discounts, club card or similar454 program; provided, that: (i) the controller shall not sell personal data to a third party as part of455 such program unless such sale is clearly and conspicuously disclosed in the terms of the456 program; and (ii) the sale of personal data shall not be a condition of participation in the457 program.458(2) A controller shall not use financial incentive practices that are unjust, unreasonable,459 coercive or usurious in nature.460Section 8. (a) A controller shall provide consumers with a reasonably accessible, clear461 and not misleading privacy notice that shall include:462(i) the categories of personal data collected and processed by the controller, including a463 separate list of categories of sensitive data collected and processed by the controller, described in464 a level of detail that provides consumers with an understanding of the type of personal data465 collected or processed;466(ii) the purpose for collecting and processing each category of personal data the controller467 collects or processes described in a way that gives consumers an understanding of how each468 category of their personal data will be used;469(iii) how consumers may exercise their consumer rights, including how a consumer may470 appeal a controller’s decision with regard to the consumer’s request;471(iv) the categories of personal data that the controller sells to third parties, if any, and the472 purposes for those sales;23 of 38473(v) the categories of third parties, if any, to which the controller sells personal data;474(vi) the length of time the controller intends to retain each category of personal data, or, if475 it is not possible to identify the length of time, the criteria used to determine the length of time476 the controller intends to retain categories of personal data; and477(vii) an active electronic mail address or other online mechanism that the consumer may478 use to contact the controller.479(b)(1) The privacy notice shall be provided directly to consumers and made publicly480 available online. If a controller makes a material change to its privacy notice, the controller shall481 notify each consumer affected by the material change before implementing the material change482 with respect to prospectively collected personal data and shall provide a reasonable opportunity483 for each consumer to withdraw affirmative consent. The controller shall take all reasonable484 electronic measures to provide direct notification regarding material changes to the privacy485 notice to each affected consumer, taking into account available technology and the nature of the486 relationship.487(2) A controller shall provide a reasonable opportunity for each consumer to affirmatively488 consent to further materially different processing or sale of previously collected personal data489 under the changed notice.490(c) If a controller sells personal data to third parties or processes personal data for491 targeted advertising, the controller shall clearly and conspicuously disclose in the privacy notice492 such sales or processing and the manner in which a consumer may exercise the right to opt out of493 such sales or processing.24 of 38494(d)(1) A controller shall establish, and shall describe in a privacy notice, not less than 2495 secure and reliable means for consumers to submit a request to exercise their consumer rights496 pursuant to this chapter. Such means shall take into account the ways in which consumers497 normally interact with the controller, the need for secure and reliable communication of such498 requests and the ability of the controller to authenticate the identity of the consumer making the499 request. A controller shall not require a consumer to create a new account to exercise consumer500 rights but may require a consumer to use an existing account.501(2) Any means for a consumer to exercise their consumer rights established pursuant to502 paragraph (1) shall include allowing a consumer to opt out of any collection or processing of the503 consumer’s personal data for the purposes of targeted advertising, or any sale of the consumer’s504 personal data, through an opt-out preference signal sent, with such consumer’s consent, by a505 platform, technology or mechanism to the controller indicating such consumer’s intent to opt out506 of any such processing or sale. Such platform, technology or mechanism shall: (i) be consumer-507 friendly and easy to use by the average consumer; and (ii) enable the controller to reasonably508 determine whether the consumer is a resident of the commonwealth and whether the consumer509 has made a legitimate request to opt out of any sale of such consumer’s personal data or targeted510 advertising. For purposes of this subsection, the use of an internet protocol address to estimate511 the consumer’s location shall be considered sufficient to reasonably determine residency.512(3) If a consumer’s decision to opt out of any processing of the consumer’s personal data513 for the purposes of targeted advertising, or any sale of personal data, through an opt-out514 preference signal sent in accordance with this subsection conflicts with the consumer’s existing515 controller-specific privacy setting or voluntary participation in a controller’s financial incentive516 program, including a bona fide loyalty, rewards, premium features, discounts, club card or25 of 38517 similar program, the controller shall comply with such consumer’s opt-out preference signal but518 may notify such consumer of such conflict and provide to such consumer the choice to confirm519 such controller-specific privacy setting or participation in such program.520Section 9. (a) A processor shall adhere to the instructions of a controller and shall assist521 the controller in meeting the controller’s obligations under this chapter. A processor’s assistance522 shall include:523(1) taking into account the nature of processing and the information available to the524 processor, by appropriate technical and organizational measures, insofar as is reasonable, to525 fulfill the controller’s obligation to respond to consumer rights requests;526(2) taking into account the nature of processing and the information available to the527 processor, by assisting the controller in meeting the controller’s obligations in relation to the528 security of processing the personal data and in relation to the notification of a breach of security529 of the system of the processor; and530(3) providing necessary information to enable the controller to conduct and document531 data protection assessments.532(b)(1) A contract between a controller and a processor shall govern the processor’s data533 processing procedures with respect to processing performed on behalf of the controller. The534 contract shall be written, binding and clearly set forth: (i) instructions for processing data; (ii) the535 nature and purpose of processing; (iii) the type of data subject to processing; (iv) the duration of536 processing; and (v) the rights and obligations of both parties, including a method by which the537 processor shall notify the covered entity of material changes to its privacy practices. The538 processor shall adhere to the instructions of the controller and shall only process the data it26 of 38539 receives from the controller to the extent necessary to provide a service requested by the540 controller, as set out in the contract.541(2) The contract between a controller and a processor shall require that the processor:542(i) ensure that each person processing personal data is subject to a duty of confidentiality543 with respect to the personal data;544(ii) at the controller’s direction, delete or return all personal data to the controller as545 requested at the end of the provision of services, unless retention of the personal data is required546 by law;547(iii) upon the reasonable request of the controller, make available to the controller all548 information in the processor’s possession necessary to demonstrate the processor’s compliance549 with the obligations in this chapter;550(iv) after providing the controller an opportunity to object, engage any subcontractor551 pursuant to a written contract that requires the subcontractor to meet the contractual and statutory552 or regulatory obligations of the processor with respect to the personal data;553(v) be prohibited from combining personal data that the processor receives from or on554 behalf of a controller with personal data that the processor receives from or on behalf of another555 person or collects from the interaction of the processor with an individual unless directed to do556 so by the controller; and557(vi) allow, and cooperate with, reasonable assessments by the controller or the558 controller’s designated assessor, or the processor may arrange for a qualified and independent559 assessor to conduct an assessment of the processor’s policies and technical and organizational27 of 38560 measures in support of the obligations under this chapter, using an appropriate and accepted561 control standard or framework and assessment procedure for such assessments; provided, that the562 processor shall provide a report of such assessment to the controller upon request.563(3) Nothing in the contract pursuant to paragraphs (1) and (2) shall relieve a controller or564 processor from the liabilities imposed on the controller or processor by virtue of such controller’s565 or processor’s role in the processing relationship, as described in this chapter.566(c) A processor shall establish, implement and maintain reasonable administrative,567 technical and physical data security practices to protect the confidentiality, integrity and568 accessibility of personal data appropriate to the volume and nature of the personal data at issue.569(d) Determining whether a person is acting as a controller or processor with respect to a570 specific processing of personal data shall be a fact-based determination that depends upon the571 context in which personal data is to be processed. A person who is not limited in such person’s572 processing of personal data pursuant to a controller’s instructions, or who fails to adhere to such573 instructions, shall be considered a controller and not a processor with respect to a specific574 processing of personal data. A processor that continues to adhere to a controller’s instructions575 with respect to a specific processing of personal data shall remain a processor. If a processor576 begins, alone or jointly with others, determining the purposes and means of the processing of577 personal data, the processor shall be considered a controller with respect to such processing and578 may be subject to an enforcement action under this chapter.579(e) A processor shall not process personal data on behalf of a controller if the processor580 has actual knowledge that the controller has violated this chapter with respect to such personal581 data.28 of 38582Section 10. (a) For the purposes of this section, the words “processing activities that583 presents a heightened risk of harm to a consumer” shall include:584(1) processing personal data for the purposes of targeted advertising;585(2) the sale of personal data;586(3) processing of personal data for the purposes of profiling, where such profiling587 presents a reasonably foreseeable risk of: (A) unfair or deceptive treatment of, or unlawful588 disparate impact on, consumers; (B) financial, physical or reputational injury to consumers; (C) a589 physical or other intrusion upon the solitude or seclusion, or the private affairs or concerns, of590 consumers, where such intrusion would be offensive to a reasonable person; or (D) other591 substantial injury to consumers;592(4) processing of sensitive data; and593(5) processing of personal data where such personal data was processed through a594 consumer’s use of a product or service predominantly used by minors.595(b) A controller shall conduct and document a data protection assessment for each of the596 controller’s processing activities that presents a heightened risk of harm to a consumer.597(c) Data protection assessments shall identify: (i) the categories of personal data598 processed; (ii) the purposes for processing such personal data; (iii) whether personal data is being599 sold; and (iv) weigh the benefits that may flow, directly and indirectly, from the processing to the600 controller, the consumer, other stakeholders and the public against the potential risks to the rights601 of the consumer associated with such processing, as mitigated by safeguards that are employed602 by the controller to reduce such risks. The controller shall factor into any such data protection29 of 38603 assessment the use of de-identified data and the reasonable expectations of consumers, as well as604 the context of the processing and the relationship between the controller and the consumer whose605 personal data will be processed.606(d) The attorney general may require a controller to disclose any data protection607 assessment that is relevant to an investigation conducted by the attorney general, and the608 controller shall make the data protection assessment available to the attorney general. The609 attorney general may evaluate the data protection assessment for compliance with the610 responsibilities in this chapter. To the extent any information contained in a data protection611 assessment disclosed to the attorney general includes information subject to attorney-client612 privilege or work product protection, such disclosure shall not constitute a waiver of such613 privilege or protection.614(e) A single data protection assessment may address a comparable set of processing615 operations that include similar activities.616(f) If a controller conducts a data protection assessment for the purpose of complying617 with another applicable law or regulation, the data protection assessment shall be deemed to618 satisfy the requirements established in this section if such data protection assessment is619 reasonably similar in scope and effect to the data protection assessment that would otherwise be620 conducted under this section.621(g) A controller shall review and update the data protection assessment as often as622 appropriate.623Section 11. (a) Any controller who has collected or processed personal data and is in624 possession of de-identified data shall:30 of 38625(1) take technical measures to ensure that the personal data cannot be associated with an626 individual;627(2) publicly commit to maintaining and using de-identified data without attempting to re-628 identify the personal data; and629(3) contractually obligate any recipients of the de-identified data to comply with all630 provisions of this chapter.631(b) Nothing in this chapter shall be construed to require a controller or processor to:632(1) re-identify de-identified data;633(2) maintain data in identifiable form or collect, obtain, retain or access any data or634 technology, in order to be capable of associating an authenticated consumer request with635 personal data; or636(3) comply with an authenticated consumer rights request if the controller: (A) is not637 reasonably capable of associating the request with the personal data or it would be unreasonably638 burdensome for the controller to associate the request with the personal data; and (B) does not639 use the personal data to recognize or respond to the specific consumer who is the subject of the640 personal data, or associate the personal data with other personal data about the same specific641 consumer.642(c) A controller that sells de-identified data shall exercise reasonable oversight to monitor643 compliance with any contractual commitments to which the de-identified data is subject and644 shall take appropriate steps to address any breaches of those contractual commitments.31 of 38645Section 12. (a) Nothing in this chapter shall be construed to restrict a controller’s or646 processor’s ability to:647(1) comply with federal, state or municipal ordinances or regulations;648(2) comply with a civil, criminal or regulatory inquiry, investigation, subpoena or649 summons by federal, state, municipal or other governmental authorities, except as prohibited by650 another law, including, but not limited to, section 115 of chapter 93;651(3) cooperate with law enforcement agencies concerning conduct or activity that the652 controller or processor reasonably and in good faith believes may violate federal, state or653 municipal ordinances or regulations;654(4) investigate, establish, exercise, prepare for or defend legal claims;655(5) provide, maintain, improve or update a product or service specifically requested by656 the consumer;657(6) perform under a contract to which a consumer is a party, including fulfilling the terms658 of a written warranty;659(7) take steps at the request of a consumer prior to entering into a contract;660(8) take immediate steps to protect an interest that is essential for the life or physical661 safety of the consumer or another individual, and where the processing cannot be manifestly662 based on another legal basis;663(9) prevent, detect, protect against or respond to security incidents, identity theft, fraud,664 harassment, malicious or deceptive activities or any illegal activity targeted at or involving the32 of 38665 controller or processor or its services, preserve the integrity or security of systems or investigate,666 report or prosecute those responsible for any such action;667(10) assist another controller, processor or third party with any of the obligations under668 this chapter;669(11) process personal data for reasons of public interest in the area of public health,670 community health or population health, but solely to the extent that such processing is: (A)671 subject to suitable and specific measures to safeguard the rights of the consumer whose personal672 data is being processed; and (B) under the responsibility of a professional subject to673 confidentiality obligations under federal, state or local law;674(12) ensure the data security and integrity of personal data as required by this chapter,675 protect against spam or protect and maintain networks and systems, including through676 diagnostics, debugging and repairs;677(13) effectuate a product recall pursuant to federal or state law or to fulfill a warranty;678(14) conduct medical research in compliance with 45 C.F.R. part 46 or 21 C.F.R. parts 50679 and 56;680(15) publish entity-based member or employee contact information where such681 publication is intended to allow members of the public to contact such entity-based member or682 employee in the ordinary course of the entity’s operations;683(16) process personal data previously collected in accordance with this chapter such that684 the personal data becomes de-identified data, including to: (A) conduct internal research to685 develop, improve or repair products, services or technology; (B) identify and repair technical33 of 38686 errors that impair existing or intended functionality; or (C) perform internal operations that are687 reasonably aligned with the expectations of the consumer or reasonably anticipated based on the688 consumer’s existing relationship with the controller, or are otherwise compatible with processing689 data in furtherance of the provision of a product or service specifically requested by a consumer690 or the performance of a contract to which the consumer is a party;691(17) provide information or feedback to the consumer either in response to a query or for692 the purpose of providing a product or service requested by the consumer; or693(18) with the consent of the consumer, collect or process the consumer’s biometric data694 using facial recognition technology for the purposes of permitting entry to a ticketed event in a695 location closed to the public; provided, that the biometric data shall not be used for any other696 purpose and shall be de-identified as soon as practicable; and provided further, that no biometric697 data shall be sold to any third party.698(b) The obligations imposed on controllers or processors under this chapter shall not699 apply where compliance by the controller or processor with this chapter would violate an700 evidentiary privilege under the laws of the commonwealth. Nothing in this chapter shall be701 construed to prevent a controller or processor from providing personal data concerning a702 consumer to a person covered by an evidentiary privilege under the laws of the commonwealth703 as part of a privileged communication.704(c)(1) A controller or processor that discloses personal data to a processor or third party705 controller in accordance with this chapter shall not be deemed to have violated this chapter if the706 processor or third party controller that receives and processes such personal data violates this707 chapter; provided, that at the time the controller or processor disclosed such personal data, the34 of 38708 disclosing controller or processor did not have actual knowledge that the receiving processor or709 third party controller would violate this chapter.710(2) A third party controller or processor receiving personal data from a controller or711 processor in compliance with this chapter shall not be in violation of this chapter for the712 transgressions of the controller or processor from which such third party controller or processor713 receives such personal data.714(d) Nothing in this chapter shall be construed to: (i) impose any obligation on a controller715 or processor that adversely affects the rights or freedoms of any person, including, but not716 limited to, the rights of any person to freedom of speech or freedom of the press guaranteed in717 the First Amendment to the United States Constitution or Article XVI of the Declaration of718 Rights; or (ii) apply to any person’s collection or processing of personal data in the course of719 such person’s purely personal or household activities.720(e) Personal data collected or processed by a controller under this section may be721 collected or processed to the extent that such collection and processing is consistent with this722 chapter.723Section 13. (a) The attorney general shall promulgate rules or regulations to implement724 this chapter, including, but not limited to, rules and regulations that establish:725(i) baseline technical requirements that determine if a given dataset has been or can be726 considered sufficiently de-identified;727(ii) reasonable administrative, technical and physical data security practices that satisfy728 the requirements set forward in paragraph (4) of section 6;35 of 38729(iii) a nonexclusive list of practices that constitute dark patterns or otherwise violate the730 requirements of this chapter regarding a consumer’s affirmative consent;731(iv) a nonexclusive list of data collection or processing practices that constitute unfair or732 deceptive practices in trade or commerce;733(v) the frequency for which the controller shall review and update the data protection734 assessment under section 10; and735(vi) requirements for privacy notices under section 8.736Section 14. (a)(1) A violation of this chapter shall constitute an unfair or deceptive trade737 practice for purposes of chapter 93A.738(2) Notwithstanding sections 9 and 11 of chapter 93A, the attorney general shall have739 exclusive authority to bring a civil action against any controller or processor other than a large740 data holder that violates this chapter or a regulation adopted under this chapter to:741(i) enjoin an act or practice that is in violation of this chapter or a regulation adopted742 under this chapter, including an order that an entity retrieve any personal data transferred in such743 violation;744(ii) enforce compliance with this chapter or a regulation adopted under this chapter,745 including by seeking declaratory relief;746(iii) obtain damages, including punitive damages, restitution of any money or property747 obtained directly or indirectly by any such violation and disgorgement of any profits, assets,748 property or personal data obtained directly or indirectly by any violation on behalf of the749 residents of the commonwealth;36 of 38750(iv) impose civil penalties in an amount not more than $5,000 per violation;751(v) obtain investigative costs, reasonable attorney’s fees and other litigation costs,752 including, but not limited to, expert fees, reasonably incurred; and753(vi) obtain any other and further relief as the court may deem proper.754(3) The restitution recovery for any violation of this chapter awarded as the result of a755 class action shall be reduced by any restitution amounts recovered by the attorney general for the756 same violation. Determination of damages shall be stayed until the attorney general notifies the757 court of any such recovery or that it is not seeking recovery in the matter, but in no event more758 than 1 year after a finding of liability or the filing of a stipulated judgement.759(b) The attorney general shall create, maintain and monitor a mechanism for consumers760 to report potential violations of this chapter.761(c) Annually, not later than March 1, the attorney general shall issue a report to the clerks762 of the house of representatives and senate and the chairs of the joint committee on advanced763 information technology, the internet and cybersecurity in a manner consistent with section 11 of764 chapter 12 on any enforcement actions taken pursuant to this section and the status or outcomes765 of said enforcement actions; provided, however, that such report shall relate to the enforcement766 of this chapter and its regulations; and provided further, that the attorney general may767 incorporate the report required pursuant to this subsection in the annual report pursuant to said768 section 11 of said chapter 12.37 of 38769SECTION 2. The data protection assessments required by section 10 of chapter 93M of770 the General Laws, inserted by section 1, shall not be requested by the attorney general before771 July 1, 2028.772SECTION 3. Not later than May 1, 2027, the attorney general shall promulgate rules or773 regulations required pursuant to section 13 of chapter 93M of the General Laws, inserted by774 section 1.775SECTION 4. The first report required pursuant to section 14 of chapter 93M of the776 General Laws, inserted by section 1, shall be submitted not later than March 1, 2028.777SECTION 5. Section 1 shall take effect July 1, 2027.; and by striking out the title and778 inserting in place thereof the following title: “An Act establishing the Massachusetts consumer779 data privacy act.”.38 of 38
Site Information & Links
Sponsors
Rep. House Committee on Ways and Means sponsors H 5472 alone.
History
H 5472 has taken 2 actions since Jun 4, 2026.
| Chamber | Action | |||
|---|---|---|---|---|
Jun 4, 2026 | House | Text of an amendment, see S2619 | ||
Jun 4, 2026 | House | Published as amended, see H5479 |
Votes
H 5472 has not gone to a roll call.
Source: malegislature.gov · legiscan.com