We’re working hard, in coalition with a whole heap of other advocacy groups, to pass the first good general commercial privacy law for Massachusetts. It’s going surprisingly well. There’s a lot of legislative support, and it helps that people’s privacy is much in the news.
The Senate already passed their version, which had limitations – most notably, that it didn’t include a “private right of action” to enable individuals to sue corporations for violating their privacy.
Now, we’re working on the House, where the “Massachusetts Consumer Data Privacy Act” has been reported out of committee with a private right of action, and is with the Ways and Means Committee – the last step before reaching the floor for a vote. House Ways and Means is now under heavy industry pressure to weaken the bill before it gets there, which is what happened in the Senate.
We’re therefore urging Ways and Means members, and House legislators more generally, to report the MCDPA out favorably, without weakening it, and with four important strengthening amendments. These are:
- THRESHOLDS TO SUE: “EITHER/OR”, NOT “BOTH/AND”
Our first recommendation is to change H.4746’s language relating to the ability of private individuals to sue corporations that violate H.4746’s privacy rules. The Senate bill has no private right of action. The House bill’s private right of action is very limited. It sets a high, dual threshold, limiting it to corporations that have both over $200m in gross annual revenue and data on two million consumers. This dual barrier will enable certain companies that are collecting a lot of data, like phone apps, to slide under the radar.
- It would prevent private enforcement against companies like Flock Safety, which has a gross annual revenue of $285 million, but which doesn’t transfer the data of over 2 million consumers. Continuous collection of ALPR data enables determination of where people live and work; Flock shares its AI predictive analytic tool which determines “patterns of driving” and labels vehicles as potentially involved in narco-trafficking, leading to wrongful arrests of U.S. citizens. Penlink, which is providing ICE and CBP with the geolocation information for cell phones across entire neighborhoods, also fails to meet the threshold because it has a gross annual revenue of only $36 million.
Therefore, we’re suggesting that private individuals should be able to sue corporations that meet either of these thresholds.
- PROTECT THE PRIVACY OF PEOPLE’S “PHILOSOPHICAL BELIEFS”
The federal government is investigating people to see if they pose a national security risk on the basis of their social media posts, communications or web searches. The President’s NSPM-7 memorandum declares philosophical beliefs like “anti-Americanism, anti-capitalism, and anti-Christianity; support for the overthrow of the United States Government; extremism on migration, race, and gender; and hostility towards those who hold traditional American views on family, religion, and morality”, as views that justify investigation of Americans by a Joint Terrorism Task Force (JTTF). Attorney General Bondi ordered the FBI’s JTTFs to prioritize the investigation of Americans with these beliefs, and ordinary Americans, like Renee Nicole Good, are being deemed “domestic terrorists” for nothing more than being in ICE’s way. A simple fix can protect the beliefs that we express in social media and communications, by including “philosophical beliefs” in the definition of sensitive data, as is already done in California’s Consumer Data Privacy Act.
- IMPROVE PROTECTION OF CHILDREN’S DATA
The Senate bill, S. 2619, says that data controllers are liable for mishandling “personal data of a consumer that a controller knows, or should have known, is a minor”. H.4746 changes this to “personal data of a consumer that a controller knows, or willfully disregards, is a minor.” That’s a significant weakening of the standard. It will be very hard for people suing a data controller to prove that the data controller “willfully disregarded” that the person whose data they mishandled was a minor. The Senate language is significantly better, and bringing the House language into line with the Senate’s in this respect would simplify the conferencing process.
- YOUR “GENETIC DATA” SHOULD NOT JUST INCLUDE YOUR DNA
The definition of sensitive data in the Senate bill includes “(iii) genetic, neural or biometric data” and “information derived therefrom.” This means that not only your DNA profile itself, but interpretive data, such as what 23andMe interprets your DNA profile to mean in terms of susceptibility to diseases or your inferred relationship to another person, would be classed as sensitive data. Similarly, not only the data “net” of your facial features created by facial recognition, but the fact that your face is interpreted as a 95% match to a criminal suspect, ought to qualify as sensitive data. So, we think that it is important to protect all data derived from cataloging the expression of our RNA and proteome. This could be accomplished by changing “genetic data” to “genomic data” (please see https://www.law.cornell.edu/cfr/text/28/202.224), and including the Senate’s phrase “information derived therefrom.”
LEGISLATIVE TEXT FOR THESE AMENDMENTS:
https://docs.google.com/document/d/1SgtWqTgLxSgWjw0hPp-BFfMGWeSlz2grgx4EHADiDS8/edit?tab=t.0

