Skip to content

Compliance Building

Doug Cornelius on compliance for private equity real estate

Menu
  • Home
  • About
    • About
    • About Doug
    • About This Website
    • Why I Blog
    • Speaking Engagements
    • Contact
    • Publications
  • Archives
    • Topic Archive
    • Book Reviews
    • Most Popular
  • Subscribe
  • Disclaimers
    • Disclaimers
    • Policies and Procedures
    • Use of Site Content
    • Comments
    • FTC Disclosure
Menu

Bingham Presentation on Massachusetts Data Security Law

Posted on January 14, 2009August 18, 2009 by Doug Cornelius
Print Friendly, PDF & Email

bingham_logoBingham McCuthen LLP put together a panel presentation on the Complying with Massachusetts New Data Security Regulations.

Mark Robinson, a partner at Bingham, started with an introduction of the law and panel. He called the law “perilous.”

Beth Boland, a partner at Bingham, went through the requirements of the new law. OCBR and the business community seem to be at a disconnect over the law. OCBR thinks that they are not a big deal. They cite a statistic that there were over 318 reported breaches that affects more than 500 Massachusetts residents during a 10 month period when they were considering the law. [See Report of M.G.L. Chapter 93h Notifications (.pdf)]

Beth highlighted the limitation that data should only be collected that is “reasonable necessary to accomplish the legitimate purpose for which it is collected” 201 CMR §17.03(g) is unique to Massachusetts.

Beth highlights one of the pitfalls being the cascading certifications. First, there is no standard for certification. She expects there will be some battle over acceptable forms. Second, you need to folow the certification process all the way down the chain of custody to your providers, the sub-providers, the sub-sub providers, etc.

Beth highlighted that May 1, 2009 is deadline for getting contractual agreement that service providers will comply and January 1, 2010 is the deadline for getting a compliance certification.

Doug Schwarz, a partner at Bingham,  pointed out that in some organizations, the requirements will mostly affect Human resources and that HR may end up driving the process instead of IT.

Share this:

  • Click to print (Opens in new window) Print
  • Click to share on Facebook (Opens in new window) Facebook
  • Click to share on LinkedIn (Opens in new window) LinkedIn
  • Click to share on X (Opens in new window) X
  • Click to email a link to a friend (Opens in new window) Email

Leave a ReplyCancel reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Search for Stuff

Recent Stories

  • Compliance Bricks and Mortar for January 16
  • Staff Report on Capital-Raising Dynamics
  • Compliance Bricks and Mortar for January 9
  • “Small”: I Don’t Think You Know What That Means
  • CFTC is Saying Goodbye to Private Funds
  • New York’s LLC Transparency Act Will Remain Limited
  • SEC and CFTC With Only Republicans
  • Compliance Books from 2025
  • Happy New Year
  • The One That Can Drive You and Give You Investment Advice

Fight Cancer

Please support my Pan-Mass Challenge
Make a donation to fight cancer. donate.pmc.org/DC0176
pan-mass challenge badge

I am a lawyer, but I am not your lawyer. Since I’m a lawyer, this website may be considered attorney advertising under the ethical rules of certain jurisdictions. Please read my disclaimers page before taking any action. And then, don't take any action based on what I wrote.

Creative Commons logo with the text 'Some Rights Reserved' and three symbols representing attribution, non-commercial use, and share alike.

Compliance Building - by Doug Cornelius is licensed under a Creative Commons Attribution-Noncommercial 3.0 United States License.