2 ms·
>Attaching serious liability to holding data on systems that aren't secured That was the intent with Massachusetts PII law 201 CMR 17 which stipulates a $5000
by markc 12y ago
>Attaching serious liability to holding data on systems that aren't secured
That was the intent with Massachusetts PII law 201 CMR 17 which stipulates a $5000 fine per incident. I've always heard this interpreted as "per user record exposed" though apparently that's in dispute. $5k per exposed user could add up, but so far I don't think the law has had much impact. (btw it applies to anyone holding MA resident's data wherever the company is located / data is stored). California has a similar (earlier) law I believe. Perhaps we need this to be adopted at the Federal level.