Sources

Verified August 25, 2026

The regulation behind the document.

Shieldwise is built against the published text of two state data-security sources. Below is a plain-English summary of the provisions our templates track — each cited summary links to the official text, and every entry is date-stamped so you can see when we last checked it.

How to use this page

This page is research, not counsel. Read it as a map of what the regulation says and where to find the original. For your specific facts, contracts, and any material amendments, confirm with a licensed attorney in your state. We re-verify each entry on a known cadence; the badge above and the date on each provision reflect the last time we opened the link.

What Shieldwise covers

The current Shieldwise scope is limited to Massachusetts 201 CMR 17.00 and New York General Business Law § 899-bb (SHIELD Act). These sources provide the structure for a working document; this page and the product do not determine whether a source applies to a particular business. Other obligations require separate review with counsel.

Massachusetts

201 CMR 17.00

201 CMR 17.00 — Standards for the Protection of Personal Information of Residents of the Commonwealth of Massachusetts

Regulator: Office of the Massachusetts Attorney General. The full text of the regulation is maintained at www.mass.gov/regulations/201-CMR-17.

Purpose and scope

201 CMR 17.01

Sets out the regulation's purpose and describes its scope by reference to persons who own or license personal information about a Massachusetts resident; that can include small businesses without a dedicated security team.

Read on mass.govVerified August 25, 2026
Definitions — what counts as "personal information"

201 CMR 17.02

Defines "personal information" as a resident's first name (or initial) plus last name in combination with one of: Social Security number, driver's license or state ID number, financial account number (with the access code), or credit/debit card number (with the access code). The definition drives what the rest of the regulation protects.

Read on mass.govVerified August 25, 2026
Safeguards for personal information

201 CMR 17.03

Requires every covered person to develop, implement, and maintain a comprehensive Written Information Security Program (WISP) that is "reasonably sized" to the scale and complexity of the business, the sensitivity of the data, and the resources available. Identifies three families of safeguards — administrative, technical, and physical — that the WISP must address.

Read on mass.govVerified August 25, 2026
Computer system security requirements

201 CMR 17.04

Specifies the technical controls a WISP must include: unique user IDs, secure authentication (with password complexity and lockout), encryption of personal information in transit and at rest where reasonable, secure access control, monitoring of system access for unauthorized activity, firewalls and up-to-date security patches, and secure development practices for in-house applications.

Read on mass.govVerified August 25, 2026
Security awareness training

201 CMR 17.05

Requires ongoing training for all employees who handle personal information, addressing the risks the regulation names in 17.04 and the obligations of the WISP itself. Imposes it on new hires and repeats it when the program is materially updated.

Read on mass.govVerified August 25, 2026

New York

N.Y. Gen. Bus. Law § 899-bb

New York General Business Law § 899-bb — SHIELD (Stop Hacks and Improve Electronic Data Security) Act

Regulator: Office of the New York Attorney General. The full text of the regulation is maintained at www.nysenate.gov/legislation/laws/GBS/899-BB.

Definitions — "private information"

N.Y. Gen. Bus. Law § 899-bb(1)

Defines "private information" to include personal information in combination with a non-truncated Social Security number, driver's licence or non-driver ID number, financial account number with access credentials, biometric information, and a username/email paired with a password or security question answer that would permit account access. The definition tracks the kinds of records a small business usually holds for clients, employees, or both.

Read on nysenate.govVerified August 25, 2026
Data security program — what the SHIELD Act requires

N.Y. Gen. Bus. Law § 899-bb(2)

Requires any person or business that owns or licenses "private information" of a New York resident to maintain a data security program that includes reasonable administrative, technical, and physical safeguards — sized to the nature and scope of the activity, the sensitivity of the information, and the resources available. Breaches involving covered data trigger notification obligations handled separately under other New York statutes.

Read on nysenate.govVerified August 25, 2026
Small-business standard

N.Y. Gen. Bus. Law § 899-bb(3)

Describes safeguards for a small business as appropriate to its size and complexity, the nature and scope of its activities, and the sensitivity of the information it collects. Small-business status affects how the standard is sized; it does not let Shieldwise determine whether a particular business's program meets the law.

Read on nysenate.govVerified August 25, 2026

A note on legal advice

Shieldwise assembles a state-specific scaffold grounded in the published text of the cited regulation — not legal advice, and not a substitute for counsel. Final adoption and any material amendments should be reviewed with a licensed attorney admitted in the state whose requirements apply to your program. Nothing on this site or in the documents we generate creates an attorney-client relationship with Shieldwise, its operators, or its affiliates.