SECURITY ADDENDUM (ENTERPRISE SAAS)
Massachusetts Jurisdictional Version
KEY PROVISIONS
Data Breach Notification (M.G.L. c. 93H)
- Notify as soon as practicable and without unreasonable delay
- Notify Massachusetts Attorney General and Office of Consumer Affairs
- Written notice with description, type of info, steps taken, contact info
Data Security Standards (201 CMR 17.00)
- Provider must maintain comprehensive Written Information Security Program (WISP)
- Risk assessments, encryption of transmitted personal info, access controls
- Employee training, vendor management
Personal Information Definition
Name with: SSN, driver's license, financial account, credit/debit card.
Trade Secrets
M.G.L. c. 93 Section 42
E-Signatures
M.G.L. c. 110G
Late Payment
6% default; 18% for business (M.G.L. c. 231 Section 6C)
Forum
Massachusetts (exclusive). Jury waiver permitted.
EXECUTION
☐ Master Agreement referenced ☐ WISP compliance verified ☐ Massachusetts-licensed counsel review