If you run a business in Massachusetts and you hold any personal information about a Massachusetts resident, one regulation applies to you whether you have heard of it or not. It is called 201 CMR 17.00, and it sets some of the strictest data protection rules in the country. This guide explains what the law requires in plain language, who it covers, and how proper document destruction is one of the simplest parts to get right.
In This Article
- What is 201 CMR 17.00
- What counts as personal information
- Who the regulation covers
- What the regulation requires
- What happens if you do not comply
- How professional shredding satisfies the disposal standard
- A practical disposal checklist
- How 201 CMR 17.00 fits with other privacy rules
- Common 201 CMR 17.00 disposal mistakes
- Frequently asked questions
Most coverage of 201 CMR 17.00 quotes the statute and leaves you to figure out what to actually do. This guide does the opposite. It explains the rule, then focuses on the practical disposal obligations that a business owner, office manager or compliance lead can act on right away.
What is 201 CMR 17.00
201 CMR 17.00 is a Massachusetts regulation, formally titled the Standards for the Protection of Personal Information of Residents of the Commonwealth. It was issued under the state’s data security law, M.G.L. chapter 93H, and it has been in force since 2010.
The core idea is straightforward. Any person or business that owns or licenses personal information about a Massachusetts resident must protect that information with a written, comprehensive information security program. The regulation covers personal information in every form, both electronic and paper.
What makes the Massachusetts rule notable is that it applies based on whose data you hold, not where your business sits. A company in another state that holds personal information about Massachusetts residents is still subject to it. For a Boston-area business, that simply means the rule almost certainly applies to you.
What counts as personal information
The regulation is specific about what it protects. Personal information means a Massachusetts resident’s first name or first initial and last name, combined with any one of these data elements:
- Social Security number
- Driver’s license number or state-issued identification card number
- Financial account number, or credit or debit card number, with or without any security code or password that would permit access to the account
This is broader than people assume. A spreadsheet of customers with names and credit card numbers qualifies. A folder of employee files with names and Social Security numbers qualifies. A stack of old loan applications qualifies. If your business touches any of these, the regulation governs how you store, handle and dispose of them.
The simple test: if a document pairs a person’s name with their Social Security number, driver’s license number, or financial account number, it is personal information under 201 CMR 17.00, and it cannot be thrown in the trash intact.
Who the regulation covers
The reach is wide. The regulation applies to any person or entity that owns or licenses personal information about a Massachusetts resident in connection with employment or the provision of goods or services.
In practice that includes nearly every business with employees or customers in Massachusetts. A few examples from the Boston area:
- A retail shop that keeps customer payment records
- A medical or dental practice with patient files, also subject to HIPAA
- A law firm holding client financial information
- An accounting practice with client tax records
- Any employer with personnel files containing Social Security numbers
- A property manager or real estate office with tenant or buyer applications
Size does not exempt you. A small business with a handful of employees is covered the same as a large company. The regulation does allow the security program to be scaled to the size and resources of the business, but the obligation itself does not disappear.
What the regulation requires
201 CMR 17.00 asks covered businesses to maintain a written information security program with administrative, technical and physical safeguards. The full program covers many areas, including employee training, access controls, computer security and vendor oversight.
For the purposes of this guide, the part that matters most is disposal. The regulation, read together with the broader Massachusetts data disposal law, requires that when records containing personal information are no longer needed, they are destroyed so the personal information cannot be read or reconstructed.
For paper records, that means the documents must be redacted, burned, pulverized or shredded so personal information cannot practically be read or reconstructed. For electronic media, the data must be destroyed or erased so it cannot practically be read or reconstructed. This is where a professional shredding and media destruction service does the heavy lifting for you.
What happens if you do not comply
Non-compliance is not a quiet risk. Massachusetts chapter 93H also includes a breach notification requirement. If personal information is acquired or used by an unauthorized person, the business must notify the affected residents and state regulators.
Improper disposal is one of the clearest ways a breach happens. Intact files in a dumpster, an old hard drive that is sold without being wiped, a box of personnel records left in an unsecured space. Each can trigger a reportable breach. From there, a business can face regulatory enforcement, financial penalties, the cost and disruption of breach notification, and lasting damage to its reputation with customers.
Our article on the true cost of a data breach walks through how quickly those costs add up. The point for compliance planning is simple: disposal is a low-cost obligation to meet, and an expensive one to fail.
How professional shredding satisfies the disposal standard
Of all the parts of a 201 CMR 17.00 program, disposal is one of the most straightforward to handle well, because you can outsource it to a process built for the purpose.
A professional shredding service meets the standard in concrete ways:
- It renders personal information unreadable. Industrial cross-cut shredding destroys documents so personal information cannot practically be read or reconstructed, which is exactly the language the disposal standard uses.
- It provides documented proof. A Certificate of Destruction records what was destroyed and when. If a regulator asks how you disposed of personal information, that certificate is your answer.
- It maintains a chain of custody. Secure collection and tracked handling close the gap between “we set the files aside” and “the files were destroyed.”
- It covers electronic media. The same standard applies to hard drives, so a service that destroys drives helps you meet the electronic side of the rule.
You can bring records to our Tewksbury drop-off facility, arrange pickup and off-site shredding for larger volumes, or set up a scheduled service so disposal happens on a routine cycle rather than as an afterthought.
Make compliant disposal the easy part
We destroy documents and media to a standard that meets 201 CMR 17.00 disposal requirements, with a Certificate of Destruction every time. Serving Boston-area businesses since 2007.
Schedule Shred Now Call (978) 636-0301A practical disposal checklist
Here is how to turn the disposal piece of 201 CMR 17.00 into a routine your business actually follows.
- Identify what you hold. Walk through where personal information lives in your business: customer files, employee records, financial paperwork, old applications, backup drives.
- Set retention windows. Decide how long each record type needs to be kept, then dispose of it once that window closes. Our document retention guide can help.
- Secure records awaiting destruction. Files waiting to be shredded should be in a locked container, not an open bin.
- Use a professional destruction service. Shred paper and destroy media through a service that issues a Certificate of Destruction.
- Keep the certificates. File every Certificate of Destruction. Together they are your documented proof of compliant disposal.
- Make it recurring. A scheduled purge prevents the slow build-up of unaddressed records.
This guide explains the disposal side of 201 CMR 17.00. The regulation also covers training, access controls and computer security, and a full written information security program should address those too. For legal certainty on your specific obligations, consult an attorney familiar with Massachusetts data security law.
How 201 CMR 17.00 fits with other privacy rules
The Massachusetts regulation does not exist on its own. Most Boston-area businesses face a stack of overlapping rules, and it helps to see how they relate.
HIPAA governs how healthcare providers and their partners handle protected health information. A medical or dental practice in Massachusetts must satisfy both HIPAA and 201 CMR 17.00. The good news is that compliant destruction satisfies the disposal piece of both at once.
The FACTA Disposal Rule is a federal rule covering the disposal of consumer report information, the kind of data in background checks and credit reports. Any business that uses such reports is covered.
The Gramm-Leach-Bliley Act sets data protection expectations for financial institutions, which in practice reaches banks, lenders, accounting firms and others handling financial data.
The pattern across all of them is the same. When records containing sensitive personal data reach the end of their useful life, they must be destroyed in a way that makes the information unrecoverable. A single professional destruction process, with a Certificate of Destruction, addresses the disposal requirement of every one of these rules. You do not need a separate disposal method for each law. You need one that is done properly. Our guides on FACTA compliance and GLBA compliance cover those rules in more depth.
Common 201 CMR 17.00 disposal mistakes
A few errors show up repeatedly when businesses handle disposal on their own.
Treating the recycling bin as disposal. Putting intact documents with personal information into a recycling or trash bin is not secure destruction. The records can be read by anyone who retrieves them, and the regulation expects the information to be unreadable.
Relying on an office shredder. A desktop shredder produces no Certificate of Destruction and no chain of custody. It also tempts staff to leave files in an open pile waiting to be shredded, which is an exposure in itself.
Forgetting electronic media. The regulation covers data on hard drives, not just paper. Retiring computers or selling old equipment without destroying the drives is a common and serious gap.
Letting records pile up. Without a retention schedule and a routine purge, old files accumulate. Every box of unneeded records holding personal information is unmanaged risk.
Keeping no proof. Even when disposal is done, failing to keep the Certificate of Destruction leaves you unable to demonstrate compliance later. The paperwork is part of the protection.
One mindset shift helps more than any single tactic: treat disposal as an ongoing process, not a one-time cleanup. Personal information flows into your business every week through new customers, new hires and new transactions. A program that only purges records once and then forgets about it drifts back out of compliance within a year. A standing schedule, even a quarterly or annual one, keeps the obligation met without anyone having to remember it. That is the practical difference between a business that can show a clean disposal record and one scrambling to explain a storage room full of old files.
Key takeaways
- 201 CMR 17.00 is a Massachusetts regulation requiring a written information security program for anyone holding personal information about a Massachusetts resident.
- Personal information means a name paired with a Social Security number, driver’s license number, or financial account number.
- It applies based on whose data you hold, not where your business is, and size does not exempt you.
- The disposal standard requires records to be destroyed so personal information cannot be read or reconstructed.
- Professional shredding with a Certificate of Destruction is a direct, documented way to meet the disposal obligation.
Frequently asked questions
What is 201 CMR 17.00 in simple terms?
It is a Massachusetts regulation that requires any business holding personal information about a Massachusetts resident to protect that information with a written security program. It covers data in both electronic and paper form and has been in force since 2010. One of its requirements is that records containing personal information are securely destroyed when they are no longer needed.
Does 201 CMR 17.00 apply to my small business?
Almost certainly, if you have employees or customers in Massachusetts. The regulation applies to any business that owns or licenses personal information about a Massachusetts resident. Small businesses are covered the same as large ones, though the security program can be scaled to the size and resources of the business. The disposal obligation applies regardless of size.
What does 201 CMR 17.00 require for document disposal?
Records containing personal information must be destroyed so the personal information cannot practically be read or reconstructed. For paper, that means shredding, pulverizing or burning. For electronic media, the data must be destroyed or erased so it cannot be read or reconstructed. Professional shredding and media destruction meet this standard directly.
What counts as personal information under the regulation?
Personal information is a Massachusetts resident’s first name or first initial and last name combined with a Social Security number, a driver’s license or state ID number, or a financial account, credit or debit card number. If a document pairs a name with any of those, it is personal information and must be securely destroyed when no longer needed.
What are the penalties for non-compliance?
Massachusetts chapter 93H includes a breach notification requirement. Improper disposal that leads to unauthorized access can trigger a reportable breach, regulatory enforcement, financial penalties, the cost of notifying affected residents, and reputational harm. Compliant disposal is inexpensive compared to the cost of a breach.
How does a Certificate of Destruction help with compliance?
A Certificate of Destruction documents what records were destroyed, when and by what method. If a regulator or auditor asks how your business disposed of personal information, the certificate is your evidence that disposal was handled securely. Keeping your certificates on file builds an ongoing record of compliant disposal.
Get a free shredding quote
Tell us your approximate volume and we will give you an honest price. Serving businesses across Boston, Lowell, Cambridge, Tewksbury and southern New Hampshire since 2007.
Get My Free Quote Contact Us