Massachusetts 201 CMR 17.00 and Student Records: What Actually Applies
Massachusetts is the state most often misdescribed in vendor security questionnaires, in both directions. Its information security regulation is genuinely demanding and reaches third-party service providers through your contract. Its definition of personal information is also narrower than most people assume, which means half the things districts worry about are governed by the student records regulations instead, on entirely different terms.
| Data element | “Personal information” under 201 CMR 17.00? | Student record? | Which rules bite |
|---|---|---|---|
| Student name and grade | No | Yes | Student records regulations and FERPA |
| Guardian mobile number | No, on its own | Yes, as part of the record | Student records regulations |
| Home language of record | No | Yes | Student records regulations, plus language-access duties |
| Name with Social Security number | Yes | Sometimes | Both, and the written security programme rules engage |
| Name with financial account number | Yes | Meal accounts, sometimes | Both |
| Name with driver's licence or state ID number | Yes | Staff and volunteer records | Both |
| Message content mentioning a student | Usually not | Usually yes | Student records regulations |
| Staff payroll data in a comms system | Likely | No | Written security programme rules |
The narrow definition is a real feature of the regulation, not a loophole. It exists because that regulation is aimed at identity theft. It does not mean a guardian phone number is unprotected — it means the protection comes from a different instrument, with different remedies.
The written information security programme, and the clause it puts in your contract
201 CMR 17.00 requires persons who own or license personal information about a Massachusetts resident to develop, implement and maintain a comprehensive written information security programme, with administrative, technical and physical safeguards appropriate to the size of the organisation and the sensitivity of the data.
The provision that matters in procurement is the third-party one. The regulation contemplates taking reasonable steps to select and retain service providers capable of maintaining appropriate security measures, and requiring those providers by contract to implement and maintain them. In practice that means a specific contractual undertaking, not a general assurance in a sales deck.
Two things follow for a communications procurement.
- Ask whether the vendor has a written programme, and ask when it was last reviewed. A document with a review date inside the last twelve months is worth more than a longer document with no date on it.
- Ask what personal information under the narrow definition the platform will actually hold. For most communications platforms the honest answer is very little — no Social Security numbers, no financial account numbers, no licence numbers. That is a good answer and it should be stated rather than implied, because it materially reduces the risk surface and it changes what the contract needs to say.
Kastr holds no Social Security numbers, no financial account numbers and no government identification numbers of any kind. What we hold is names, roles, contact points, home language, and message history. We are not going to pretend that makes us low-risk in general — a guardian contact database is sensitive — but it does mean the identity-theft-shaped part of the Massachusetts regime largely does not engage, and you should confirm that against your own field inventory rather than taking it from us.
Student records, and the non-custodial parent procedure
Massachusetts student records regulations sit at 603 CMR 23.00 and give parents and eligible students access to the record, with a defined timeline for producing it on request. Confirm the current timeline before you build a service-level expectation on it.
The distinctively Massachusetts provision worth knowing about in a communications context is the non-custodial parent access procedure in the general laws governing student records. Massachusetts does not simply say non-custodial parents have access; it sets out a process, with notice to the custodial parent and a waiting period, before the record is released. That is more structured than most states, and it has a direct operational consequence: a communications platform's contact list is not the right place to resolve a custody question, and a district that treats “is this person in the system” as equivalent to “is this person entitled to the record” will eventually get it wrong.
The modelling question to ask a vendor is whether a person can hold more than one role, with dates. A parent who is also a bus driver, a guardian who is also a PTA officer, a stepparent whose access begins on a court date — these are ordinary situations that flat contact lists handle badly. Kastr models one person with many effective-dated role rows rather than duplicating the person per role, which is the shape this problem needs. See who gets the message for the operational detail.
What a Massachusetts district should put in the contract
Four items, beyond the standard set.
- The service-provider security undertaking, stated as an obligation to implement and maintain safeguards, not as a representation that the vendor has a policy.
- A field inventory appendix. One page listing every data element the platform will receive. This is the cheapest document in the whole agreement and it resolves more arguments than any other.
- Breach notification to the district, with a window, a named role, and a second channel — and note that Massachusetts breach notification law has its own requirements about content and about who else must be told, which your counsel will handle.
- End-of-term handling, with export format and deletion definition stated separately, because they are separate promises and vendors routinely conflate them.
Our honest position on evidence. We can describe our controls in detail and point at the code that implements them: row-level security under a non-owner database role that fails closed, a cross-tenant leakage suite running in CI against real Postgres, a hash-chained append-only audit log, API keys stored only as SHA-256 hashes with the plaintext shown exactly once, and roster connector configuration that hard-rejects literal credentials so a district cannot paste a live key into a settings field. What we cannot give you is a SOC 2 report, because we have not been audited, or a VPAT, because we have not produced one. A vendor's willingness to say that sentence is itself a datapoint about the rest of their answers.
This page describes what a statute asks of a vendor. It is not legal advice, statutes are amended, and section numbering moves. Confirm the current text with your own counsel or your state education agency before you rely on any of it in a contract or a procurement file.
Questions people actually ask
Does 201 CMR 17.00 apply to student names and phone numbers?
Generally not on their own. The regulation's definition of personal information pairs a name with a Social Security number, a driver's licence or state ID number, or a financial account number. Student names and guardian phone numbers are protected, but through the student records regulations and FERPA rather than through that regulation.
Does a school district have to require security terms from its vendors in Massachusetts?
The regulation contemplates selecting service providers capable of maintaining appropriate safeguards and requiring them by contract to do so. In practice that means a specific contractual undertaking. Have counsel confirm how the requirement applies to your district and to each vendor's data holdings.
How does Massachusetts handle non-custodial parent access to student records?
Massachusetts sets out a defined procedure rather than a bare right, including notice to the custodial parent and a waiting period before release. Treat it as a records process owned by the records custodian, not as a contact-list question owned by the front office, and confirm the current procedure with counsel.
What should a Massachusetts district ask a communications vendor for?
A written information security programme with a recent review date, a one-page inventory of every field the platform will hold, a contractual security undertaking, a breach window with a named recipient role, and separate statements of what export and deletion actually mean at the end of the term.
One price. Every feature. Locked for three years.
$3.50 per student per year under 5,000 students. No tiers, no add-on modules, no per-message fees. Published on the site because you should not have to book a call to learn a price.