Code of Massachusetts Regulations
205 CMR - MASSACHUSETTS GAMING COMMISSION
Title 205 CMR 257.00 - Sports Wagering Data Privacy
Section 257.04 - Patron Access
Current through Register 1531, September 27, 2024
(1) Patrons shall be provided with a method to make the requests in 205 CMR 257.04(1)(a) through (e). The request must be clearly and conspicuously available to the patron online through the Sports Wagering Operator's Sports Wagering Platform. A patron shall not be required to confirm their request more than once, and no intervening pages (other than those needed to confirm withdrawal of consent) or offers will be presented to the patron before such confirmation is presented to the patron.
(2) A Sports Wagering Operator shall provide a written response to a request submitted pursuant to 205 CMR 257.o4(1) that either grants or denies the request.
(3) A Sports Wagering Operator shall grant the patron's request to impose a restriction or erase or anonymize their Confidential Information or Personally Identifiable Information if it is no longer necessary to retain the patron's Confidential Information or Personally Identifiable Information (or to retain the patron's Confidential Information or Personally Identifiable Information without the requested restriction) to operate a Sports Wagering Area, Sports Wagering Facility or Sports Wagering Platform, or for any other purpose authorized pursuant to 205 CMR 257.01; and
(4) If the Sports Wagering Operator grants the patron's request to erase or anonymize their Confidential Information or Personally Identifiable Information, the Sports Wagering Operator shall erase or anonymize the patron's Personally Identifiable Information or Confidential from all storage media it is currently using to operate a Sports Wagering Area, Sports Wagering Facility or Sports Wagering Platform, including HDD, SdD, flash, mobile, cloud, virtual, RAID, LUN, hard disks, solid state memory, and other devices. The Sports Wagering Operator shall also request commercially reasonable confirmation of deletion or anonymization from any Vendor, Registrant, or Subcontractor who received the patron's Confidential Information or Personally Identifiable Information from the Sports Wagering Operator. Notwithstanding, the foregoing, the Sports Wagering Operator shall not erase or anonymize a patron's Confidential Information or Personally Identifiable Information on backup or storage media used to ensure the integrity of the Sports Wagering Area, Sports Wagering Facility or Sports Wagering Platform from technology failure or to comply with its data retention schedule or to comply with M.G.L. c. 23N, 205 CMR, or any other applicable law, regulation, court order, subpoena or civil investigative demand of a governmental entity.
(5) An Operator, or a Vendor, Registrant or Subcontractor of an Operator shall not require a Patron to enter into an agreement waiving any of the Patron's rights under 205 CMR 257.04.