The Law Offices of Amy Mastrobattista, PC
365 Boston Post Road ~ Suite 133 ~ Sudbury, MA 01176
Office: 978-443-2779 ~ Cell: 617-470-2114
amymastro@mastrolawoffice.com
Compliance Date:
Overview:
Is Your Business Subject To The Regulations: The regulations apply to any company that “owns, licenses or maintains personal information about a resident of
The regulations apply to oral, paper and electronic records.
Definition of Personal Information: Personal Information includes: a first and last name or a first initial and last name combined with:
· A social security number
· Driver’s license number
· Financial Account number (i.e. bank account number)
· Credit or Debit Card number
Information lawfully obtained from publicly available information or from federal, state or local government records is NOT personal information under the regulations.
What Do You Need To Do: The Regulations require that by
BUT ALL BUSINESSES BIG AND SMALL must have a written plan in place.
Contents of The WISP: The WISP is a very detailed document, requiring you to cover a lot of ground. You can find the specific requirements at http://www.mass.gov/Eoca/docs/idtheft/201CMR1700reg.pdf.
Because this list is so intimidating the Massachusetts Office of Consumer Affairs has published a Compliance Checklist to help business owners draft their WISPs. You can find this checklist at:
http://www.mass.gov/Eoca/docs/idtheft/compliance_checklist.pdf.
What Should You Do Now: If you your business maintains personal information you need to
· Determine how personal information is stored in your office
· Evaluate whether any personal information is transmitted to third parties (i.e., payroll services, financial services companies)
· Determine if such third parties are complying with the regulations
· Develop a WISP
· Educate your employees about the WISP and the importance of keeping personal information safe
· Update your employee handbook to reflect the notification to employees regarding the WISP.
You should be aware that the regulations require that you select and retain vendors that hold or use the personal information of your employees and/or customer who are capable of complying with the regulations. The regulations require that your vendors by CONTRACT implement and maintain appropriate security measures. Contracts with your vendors entered into prior to
Penalties for Non-Compliance: Failure to comply with the regulations may subject you to fines by the