Categories
privacy state

Support (and amend) the Mass. Consumer Data Privacy Act

We’re working hard, in coalition with a whole heap of other advocacy groups, to pass the first good general commercial privacy law for Massachusetts. It’s going surprisingly well. There’s a lot of legislative support, and it helps that people’s privacy is much in the news.

The Senate already passed their version, which had limitations – most notably, that it didn’t include a “private right of action” to enable individuals to sue corporations for violating their privacy.

Now, we’re working on the House, where the “Massachusetts Consumer Data Privacy Act” has been reported out of committee with a private right of action, and is with the Ways and Means Committee – the last step before reaching the floor for a vote. House Ways and Means is now under heavy industry pressure to weaken the bill before it gets there, which is what happened in the Senate.

We’re therefore urging Ways and Means members, and House legislators more generally, to report the MCDPA out favorably, without weakening it, and with four important strengthening amendments. These are:

  1. THRESHOLDS TO SUE: “EITHER/OR”, NOT “BOTH/AND”

Our first recommendation is to change H.4746’s language relating to the ability of private individuals to sue corporations that violate H.4746’s privacy rules. The Senate bill has no private right of action. The House bill’s private right of action is very limited. It sets a high, dual threshold, limiting it to corporations that have both over $200m in gross annual revenue and data on two million consumers. This dual barrier will enable certain companies that are collecting a lot of data, like phone apps, to slide under the radar.

Therefore, we’re suggesting that private individuals should be able to sue corporations that meet either of these thresholds. 

  1. PROTECT THE PRIVACY OF PEOPLE’S “PHILOSOPHICAL BELIEFS”

The federal government is investigating people to see if they pose a national security risk on the basis of their social media posts, communications or web searches. The President’s NSPM-7 memorandum declares philosophical beliefs like “anti-Americanism, anti-capitalism, and anti-Christianity; support for the overthrow of the United States Government; extremism on migration, race, and gender; and hostility towards those who hold traditional American views on family, religion, and morality”, as views that justify investigation of Americans by a Joint Terrorism Task Force (JTTF). Attorney General Bondi ordered the FBI’s JTTFs to prioritize the investigation of Americans with these beliefs, and ordinary Americans, like Renee Nicole Good, are being deemed “domestic terrorists” for nothing more than being in ICE’s way. A simple fix can protect the beliefs that we express in social media and communications, by including “philosophical beliefs” in the definition of sensitive data, as is already done in California’s Consumer Data Privacy Act.

  1. IMPROVE PROTECTION OF CHILDREN’S DATA

The Senate bill, S. 2619, says that data controllers are liable for mishandling “personal data of a consumer that a controller knows, or should have known, is a minor”. H.4746 changes this to “personal data of a consumer that a controller knows, or willfully disregards, is a minor.” That’s a significant weakening of the standard. It will be very hard for people suing a data controller to prove that the data controller “willfully disregarded” that the person whose data they mishandled was a minor. The Senate language is significantly better, and bringing the House language into line with the Senate’s in this respect would simplify the conferencing process.

  1. YOUR “GENETIC DATA” SHOULD NOT JUST INCLUDE YOUR DNA

The definition of sensitive data in the Senate bill includes “(iii) genetic, neural or biometric data” and “information derived therefrom.” This means that not only your DNA profile itself, but interpretive data, such as what 23andMe interprets your DNA profile to mean in terms of susceptibility to diseases or your inferred relationship to another person, would be classed as sensitive data. Similarly, not only the data “net” of your facial features created by facial recognition, but the fact that your face is interpreted as a 95% match to a criminal suspect, ought to qualify as sensitive data. So, we think that it is important to protect all data derived from cataloging the expression of our RNA and proteome. This could be accomplished by changing “genetic data” to “genomic data” (please see https://www.law.cornell.edu/cfr/text/28/202.224), and including the Senate’s phrase “information derived therefrom.”

LEGISLATIVE TEXT FOR THESE AMENDMENTS:

https://docs.google.com/document/d/1SgtWqTgLxSgWjw0hPp-BFfMGWeSlz2grgx4EHADiDS8/edit?tab=t.0 

Categories
Mission News privacy state

Pass the Mass Digital Privacy Act

Your online identity without a good, comprehensive privacy law

Despite what industry would like us all to think, privacy is not dead!

Aren’t you tired of your data not being your own, of your digital life being carelessly smooshed up and segmented and sold across a thousand commercial and governmental databases? We’ve gotten used to putting up with what that means – the scams, the stress, the self-policing, the endless robocalls, the poorly targeted ads, the data-fueled AI chatbots and LLMs that mimic real thinking the way pink slime mimics a grass-fed steak. This is no way to live.

But it’s also not the only way to live. Here in the Commonwealth, we can do better, like Maryland and the EU have already done. Yesterday, Digital Fourth activists sent a coalition letter to Senate and House leadership, urging them to pass S.2516, the Massachusetts Digital Privacy Act. This is genuinely an excellent privacy bill — so good that industry has already swung into action against it, even though the bill is barely out of the Senate Committee on Advanced Technology (who did great work on this).

This bill includes:

  • Strong data minimization provisions, which limit:
    • the collection and use of personal data to what is reasonably necessary for a company to provide the data or service requested by a consumer
    • The collection and use of sensitive data to what is strictly necessary to provide the data or service requested by a consumer
  • A clear list of all of the kinds of data that must be regarded as sensitive.
  • Prohibition on the sale of sensitive data.
  • Requires affirmative consent of a consumer before each transfer of their personal data.
  • Provides every consumer with the right to see, correct verifiable inaccuracies in, and delete their personal data that has been collected by a company.
  • Gives consumers the right to opt out of targeted advertising or automated profiling.
  • Requiring that companies provide a clear and obvious privacy notice about their data collection practice and security measures and method to contact them for execution of all of a consumer’s rights.
  • Establishes a free automated mechanism whereby consumers can learn whether a data broker possesses their data and can request that their data be deleted.

Call your legislator to let them know they should support this bill!

COALITION LETTER: https://warrantless.org/wp-content/uploads/2025/06/MDPA-Leadership-Outreach-Letter-2025-06-12.pdf

DETAILED EXPLAINER: https://warrantless.org/wp-content/uploads/2025/06/The-Urgent-Need-for-Effective-Comprehensive-Data-Privacy-Protections-Created-in-MDPA-S.2516-.pdf

ENDORSERS:

We’re glad to say that we’re not alone in this fight: The letter was cosigned by AFL-CIO, the American Federation of Teachers, Fight for the Future, the National Council of Jewish Women, YW Boston and more, and now also the Consumer Federation of America.