M.G.L. c. 93H / 201 CMR 17.00
Requires any organization holding Massachusetts residents' personal information — including schools, with no educational exemption — to maintain a Written Information Security Program (WISP) with administrative, technical, and physical safeguards. Mandates detailed technical controls (encryption, access controls). Breach notification required promptly to the AG, OCABR, and affected residents. If a vendor has a breach of school data, vendor bears notification responsibility — contracts must assign these obligations clearly. Schools held to the same standard as financial institutions.