Code of Massachusetts Regulations
220 CMR - DEPARTMENT OF PUBLIC UTILITIES
Title 220 CMR 274.00 - Transportation Network Companies
Section 274.10 - Data Protection
Current through Register 1531, September 27, 2024
(1) A TNC shall protect from unauthorized disclosure all personal information of a Rider or Driver in the TNC's possession, including but not limited to a Rider or Driver's first name and last name, or first initial and last name, in combination with any one or more of the following data elements that relate to such individual; provided, however, that personal information shall not include information that is lawfully obtained from publicly available information, or from federal, state or local government records lawfully made available to the general public:
(2) A TNC shall notify a Rider or Driver of its use of personal information. Notification shall be unambiguous and may be through a TNC's Digital Network or website. After notification, a TNC shall obtain the consent of a Rider or Driver prior to its use of personal information. Notification and consent may be obtained by a Rider's or Driver's accepting a TNC's terms of service within its Digital Network or another means of acceptance by a Rider or Driver of the proposed use of his or her personal information.
(3) A TNC shall maintain a data security policy, in accordance with 201 CMR 17.00: Standards for the Protection of Personal Information of Residents of the Commonwealth, that protects Rider and Driver personal information, which the TNC shall file with the Division in its Permit application and renewal application.