Loading chat...
MA H633
Bill
Status
2/27/2025
Primary Sponsor
Kate Lipper-Garabedian
Click for details
AI Summary
-
Prohibits operators of educational websites, apps, and online services from engaging in targeted advertising to students, selling student information, or building profiles on students/educators except for school purposes
-
Requires operators to implement reasonable security procedures for covered information and to return or destroy data when no longer needed for K-12 purposes or upon request by the educational entity
-
Mandates that contracts between educational entities and operators include specific provisions on data collection, security safeguards, breach notification procedures, and compliance with federal/state privacy laws (FERPA, COPPA)
-
Establishes civil penalties of up to $10,000 per violation for improper disclosure, plus punitive damages for willful violations, and authorizes the commissioner to bar non-compliant operators from accessing student/educator data for at least 5 years
-
Requires the Board of Elementary and Secondary Education to promulgate data security regulations, the commissioner to appoint a chief privacy officer, and each school district to develop privacy policies, designate a student data manager, and provide annual confidentiality training to staff
Legislative Description
Relative to student and educator data privacy
Last Action
Accompanied a new draft, see H4405
8/18/2025