Skip to content

Compliance Building

Doug Cornelius on compliance for private equity real estate

Menu
  • Home
  • About
    • About
    • About Doug
    • About This Website
    • Why I Blog
    • Speaking Engagements
    • Contact
    • Publications
  • Archives
    • Topic Archive
    • Book Reviews
    • Most Popular
  • Subscribe
  • Disclaimers
    • Disclaimers
    • Policies and Procedures
    • Use of Site Content
    • Comments
    • FTC Disclosure
Menu

Bingham Presentation on Massachusetts Data Security Law

Posted on January 14, 2009August 18, 2009 by Doug Cornelius
Print Friendly, PDF & Email

bingham_logoBingham McCuthen LLP put together a panel presentation on the Complying with Massachusetts New Data Security Regulations.

Mark Robinson, a partner at Bingham, started with an introduction of the law and panel. He called the law “perilous.”

Beth Boland, a partner at Bingham, went through the requirements of the new law. OCBR and the business community seem to be at a disconnect over the law. OCBR thinks that they are not a big deal. They cite a statistic that there were over 318 reported breaches that affects more than 500 Massachusetts residents during a 10 month period when they were considering the law. [See Report of M.G.L. Chapter 93h Notifications (.pdf)]

Beth highlighted the limitation that data should only be collected that is “reasonable necessary to accomplish the legitimate purpose for which it is collected” 201 CMR §17.03(g) is unique to Massachusetts.

Beth highlights one of the pitfalls being the cascading certifications. First, there is no standard for certification. She expects there will be some battle over acceptable forms. Second, you need to folow the certification process all the way down the chain of custody to your providers, the sub-providers, the sub-sub providers, etc.

Beth highlighted that May 1, 2009 is deadline for getting contractual agreement that service providers will comply and January 1, 2010 is the deadline for getting a compliance certification.

Doug Schwarz, a partner at Bingham,  pointed out that in some organizations, the requirements will mostly affect Human resources and that HR may end up driving the process instead of IT.

Share this:

  • Print (Opens in new window) Print
  • Share on Facebook (Opens in new window) Facebook
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on X (Opens in new window) X
  • Email a link to a friend (Opens in new window) Email

Leave a ReplyCancel reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Search for Stuff

Recent Stories

  • The Performance of the SEC in 2025
  • More on the Downsizing of the SEC
  • SEC Enforcement Results for FY 2025
  • Proposed Fundamental Reforms to AML Programs
  • Is It a Truck or a Security?
  • The One with Low IQ from Pet IQ
  • The Downsizing of the SEC
  • When “Today” Is Not all of “Today”
  • Compliance Bricks and Mortar for March 27
  • The One Where Theory Meets Reality

Fight Cancer

Please support my Pan-Mass Challenge
Make a donation to fight cancer. donate.pmc.org/DC0176
pan-mass challenge badge

I am a lawyer, but I am not your lawyer. Since I’m a lawyer, this website may be considered attorney advertising under the ethical rules of certain jurisdictions. Please read my disclaimers page before taking any action. And then, don't take any action based on what I wrote.

Creative Commons logo with the text 'Some Rights Reserved' and three symbols representing attribution, non-commercial use, and share alike.

Compliance Building - by Doug Cornelius is licensed under a Creative Commons Attribution-Noncommercial 3.0 United States License.