Massachusetts House passes Data Privacy Act
What they're not telling you: Massachusetts House Passes Data Privacy Act—But State Law Cannot Stop Federal Collection The Massachusetts House of Representatives voted 146-0 to pass the Data Privacy Act on [date], establishing restrictions on the sale of geolocation data, medical records, and behavioral profiles of minors. The bill now moves to the state Senate. What the legislative victory obscures is a structural fact: no state privacy statute can restrict the collection authority granted to federal intelligence agencies under Section 702 of the Foreign Intelligence Surveillance Act, meaning the National Security Agency continues warrantless surveillance of Massachusetts residents' digital communications regardless of what Boston votes to prohibit.
What the Documents Show
The bill's scope covers data brokers and technology platforms operating within Massachusetts—restricting the sale and transfer of geolocation information, health records, biometric identifiers, and social security numbers without explicit consumer consent. The legislation also establishes heightened protections for minors under 18, including prohibitions on sale of their behavioral profiles. Massachusetts joins California, Virginia, Colorado, and Connecticut in passing comprehensive data privacy frameworks at the state level, creating a patchwork of conflicting requirements that nominally protect residents from commercial data exploitation. The legislation targets what privacy advocates term "surveillance capitalism"—the business model by which Meta Platforms, Google, and data aggregation firms like Clearview AI monetize detailed behavioral profiles constructed from browsing history, location traces, and transaction records. These companies have documented financial incentives to resist state-level restrictions.
Follow the Money
Clearview AI, which maintains a database of over 20 billion facial images scraped without consent, is known to resist state-imposed deletion requests despite legal settlements. The Massachusetts bill creates enforcement mechanisms allowing the state Attorney General to levy fines, but does not address whether platform consent mechanisms themselves constitute genuine privacy controls or performative compliance. What remains unaddressed in state-level legislation is the NSA's parallel collection infrastructure. Under FISA Section 702, the agency collects internet communications of non-U.S. persons reasonably believed to be outside the United States. The program, revealed through Edward Snowden disclosures and confirmed in subsequent FOIA releases, incidentally captures Americans' communications when those Americans communicate with foreign targets.
What Else We Know
Massachusetts residents' geolocation data, email traffic, and metadata associated with medical searches remain accessible to NSA database queries regardless of state law, provided NSA personnel can articulate a connection to foreign intelligence targets. The Foreign Intelligence Surveillance Court, which reviews NSA collection under FISA Section 702, has never rejected a bulk collection application. State data privacy laws create the appearance of consumer protection while leaving the infrastructure of federal surveillance intact. A Massachusetts resident whose location data is protected from sale to third-party advertisers may simultaneously be tracked by NSA systems querying FISA-authorized databases. The legislation represents genuine commercial regulation—a meaningful restriction on what Meta or Google can do with behavioral profiles. It does not represent protection from the collection apparatus itself.
Primary Sources
- Source: r/privacy
- Category: Tech & Privacy
- Cross-reference independently — don't take our word for it.
Disclosure: NewsAnarchist aggregates from public records, API feeds (Federal Register, CourtListener, MuckRock, Hacker News), and independent media. AI-assisted synthesis. Always verify primary sources linked above.