Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Data Privacy topic
No spam. Unsubscribe anytime.
Lawmakers weigh competing Massachusetts privacy bills; data‑minimization and enforcement emerge as fault lines
Summary
A long hearing showcased competing state privacy proposals: comprehensive frameworks (H78/H80/S33/S45) and narrower bills; witnesses split over data‑minimization language, private rights of action and entity vs. data‑level exemptions.
Get email alerts on the Data Privacy topic
No spam. Unsubscribe anytime.
Lawmakers and witnesses used a full committee hearing to press competing visions for a statewide data‑privacy framework, spotlighting sharp differences on data‑minimization, enforcement and exemptions.
The hearing included testimony for H78 (Massachusetts Consumer Data Privacy Act) and H80 (a competing model), Senate s33 and s45, and other bills that would set state rules on collection, profiling, targeted advertising and the sale of sensitive data. Industry witnesses including TechNet and the State Privacy and Security Coalition urged an approach consistent with frameworks already adopted in other states to reduce compliance costs; consumer groups, civil‑liberties organizations and advocates pressed for stricter data‑minimization, a private right of action and an explicit ban on sale of sensitive categories such as precise location, reproductive‑health related data and biometric identifiers.
Experts debated the substance and consequences of data‑minimization language. Privacy advocates said a strong minimization rule — limiting collection to what is necessary to provide a requested product or service — prevents downstream harms by blocking unnecessary hoarding of profiles used for surveillance advertising or price discrimination. Industry witnesses warned that vague or untested minimization language can be hard for businesses to implement and could have unintended consequences for small operators and targeted services.
Enforcement also divided witnesses. Consumer groups, privacy researchers and many advocates argued that state attorneys general alone will lack bandwidth to police the market effectively and urged a private right of action so harmed individuals can seek relief and deter violations. Several industry and business groups opposed a private right of action, saying it can be abused by plaintiffs’ lawyers and that AG enforcement paired with rulemaking would be preferable.
A second recurring fault line concerned exemptions. Some business groups asked for entity‑level exemptions (for industries already regulated under federal law such as finance and health) while advocates urged limited, data‑level exemptions so that the protection follows the sensitive data rather than a particular corporate label.
Committee leaders asked advocates, trade groups and state agencies for technical drafting suggestions and said they would continue hearings to reconcile the competing elements. No formal votes were taken. The committee signaled it will try to balance consumer protections with predictable compliance paths for businesses — a practical test that will shape final language later this session.
