Massachusetts · verified through August 25, 2026

Massachusetts: law status and evidence context.

Law status, direct attached-library attribution, and public enforcement context are shown separately. A zero direct total does not mean no enforcement exists.

MA · 6 requirements mapped / control outcomes supported

Law status

No verified general comprehensive law

No comprehensive consumer privacy law verified in force (Massachusetts Consumer Data Privacy Act passed the House 146-0 on June 4, 2026 and returned to the Senate)

Official name / citation
n.a.
Status / effective date
Pending legislation as of the fetched page
Principal enforcer
Massachusetts Attorney General

Direct attached-library attribution

0 cases · $0

These totals are assigned solely by the attachment’s state heading. Shared multistate totals are not allocated in full to every state.

The attached library does not enumerate participant-level allocations for every multistate matter; shared settlement totals are presented once at the national level and are not duplicated into state totals.

Official law sources

Other generally applicable PII law

M.G.L. c. 93H (security breaches), as amended by Ch. 444 of the Acts of 2018 - https://malegislature.gov/Laws/GeneralLaws/PartI/TitleXV/Chapter93H/ ; https://www.mass.gov/info-details/requirements-for-data-breach-notifications

Public enforcement context

Tier 1

Experian / T-Mobile

Experian $13.67 million; T-Mobile $2.43 million; more than $16 million combined; Massachusetts share stated as over $625,000 · November 7, 2022

Massachusetts joined multistate settlements over Experian and T-Mobile data breaches.

Legal basis: State consumer protection and data-security laws

Official case source (opens in a new tab)

Mapped control outcomes

1 personal data inventory/data map; 2 sensitive-data discovery; 3 downstream copy tracking; 8 breach blast-radius analysis; 9 retention/minimization; 10 regulator audit evidence

Kestryl can evidence where regulated personal data actually resides across structured stores and unstructured attachments/images, produce audit rows and evidence packs showing when each location was discovered and reviewed, and apply structured-data remediation modes (mask, vault, strip) to reduce exposure. It does not alter source attachments or documents, and its output is technical evidence supporting controls, not proof of legal compliance.