Massachusetts Data Privacy Law To Help Enforce Database Security | Database Journal

Massachusetts Data Privacy Law To Help Enforce Database Security

Mar 12, 2010
1 minute read

On March 1, the Massachusetts Data Privacy Law 201 CMR 17 came into effect. This law applies to any company, wherever it’s based, that keeps personal information of Massachusetts citizens; with it’s purpose being to ensure more strict protective measures are enforced in order to prevent breaches from occurring.

Companies who do not have an overarching security policy framework complying with the measures set by Massachusetts, and the means to enforce it, could pay penalties up to $5,000. The law does detail what types of security provisions companies will need, though there are no specifically required database security products; they will also need to document their security compliance policy, and will be audited against that in the future.

Basically, the law is designed to goad businesses without database security into action, and companies that already have that in place should not really need to change anything.

Database Journal Logo

DatabaseJournal.com publishes relevant, up-to-date and pragmatic articles on the use of database hardware and management tools and serves as a forum for professional knowledge about proprietary, open source and cloud-based databases--foundational technology for all IT systems. We publish insightful articles about new products, best practices and trends; readers help each other out on various database questions and problems. Database management systems (DBMS) and database security processes are also key areas of focus at DatabaseJournal.com.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.