The Worst Mistake a Landlord Can Make

There are many ways in which landlords can cross the line and get into serious trouble with their tenants, but perhaps the easiest is by misappropriating their security deposit. The security deposit belongs to the tenant, not the landlord. Period. End of story.


Yes, the landlord may be entitled to retain the security deposit at a later time, but only after jumping through several very important technical hurdles. Until then, hands off!


The Massachusetts statute governing residential security deposits is chapter 186, section 15B. It is long and confusing. Nevertheless, the statute carries heavy penalties. A landlord who mishandles a tenant’s deposit, even by mistake, may be obligated to reimburse the tenant for three times the deposit, plus attorney’s fees, plus any court costs incurred.


The basic principal is to avoid any co-mingling of the security deposit with other money. The trouble often begins when the landlord first receives the deposit. In essence, the landlord becomes a trustee of the tenant’s money. Since the deposit must be kept separate from other money, the tenant should not give a single check that combines the security deposit with any other payments. The security deposit should be paid with a separate check or money order. Payment should be made directly to the security deposit account and not to the landlord. Accepting cash for the security deposit is ill-advised since there is no way to distinguish between cash belonging to the landlord and that of the tenant. It doesn’t matter that the cash is later deposited in a separate account – the violation has already occurred.


Once accepted, the money must be placed in a separate bank account that is properly labeled as a security deposit account. In the event that the landlord becomes subject to claims of creditors, the tenants’ money must be held in an account that is clearly identified as escrow funds that do not belong to the landlord. The money may be placed in an account with other security deposits as long as the account is properly labeled and contains none of the landlord’s money.


Another common mistake by landlords is keeping any last month’s rent in the same account as the security deposit. Unlike the security deposit, last month’s rent is money that does belong to the landlord – it is simply rent that was paid in advance. So putting it in the same account with the security deposit would result in co-mingling and would be a violation of the statute.


The security deposit needs to stay in the account until the end of the tenancy. The only exception is if the tenant does not pay the rent. Here is another trap for the unwary landlord. The landlord may not deduct rent from the security deposit if the tenant has withheld paying rent for a valid reason. However, tenants often do not tell the landlord immediately why they are withholding their rent. So a landlord who is quick to withdraw funds from the account without verifying the reason for the lack of payment may be in for a nasty surprise later.


Of course, the primary purpose of the deposit is to protect the landlord in case of unpaid rent or damage beyond reasonable wear and tear. In order for the landlord to apply the security deposit, he or she must have taken several other important steps designed to protect the tenants before the deposit can be applied. These include providing a statutory “Statement of Condition” and detailed receipt at the outset of the tenancy, notification of the bank account where the money is held, paying annual interest, and providing a sworn statement itemizing any damages that are being claimed, together with evidence of the repair or cleaning costs.


The bottom line for any residential landlord is to consult an attorney to be certain you understand your rights and obligations before accepting a security deposit. The modest cost for this advice will pale in comparison to the penalties that may be faced after the damage is done.


Are you a landlord or tenant? Do you have questions about housing or real estate investment? I would love to hear from you. Please click below to let me know any comments or concerns.

By Kraft Law Firm August 24, 2026
Learn how to form an LLC in Westwood, MA and draft solid first contracts — a step-by-step local guide from filing to signing your first client agreement.
By Kraft Law Firm August 21, 2026
Navigate commercial real estate in Westwood, MA with legal insights. Learn about lease negotiations, zoning compliance, and property due diligence.
By Kraft Law Firm August 21, 2026
Resolve business disputes in Norwood, MA with effective strategies. Learn about mediation, litigation, and contract enforcement to protect your interests.
By Kraft Law Firm August 21, 2026
Learn creditor and collector rights in Dedham, MA under federal and state law. Discover collection strategies, legal remedies, and compliance requirements.
An aerial view of a city skyline at night with a bridge in the foreground.
October 28, 2024
We all know how to eat an elephant. One bite at a time at a time, of course. Implementing a comprehensive data security program is no different – for many it’s a monumental task. It can only be accomplished by setting out a manageable, step-by-step plan. Easier said than done? Probably, but that doesn’t mean a process that is impossibly difficult. The new Massachusetts data security regulation goes into effect on Monday, March 1. If you have not yet begun to plan for the deadline, then likely either you are unaware of the requirements, or you are feeling overwhelmed by them. And who would blame you in light of the seemingly endless list of tasks: Develop a written information security plan (WISP); Identify all foreseeable risks in your organization by examining every nook and cranny where data enters, leaves or is stored; Implement security policies and procedures and train your employees Secure all paper and electronic records; provide encryption Obtain written assurances from all vendors that they are compliant  Regularly monitor and review to insure compliance You know that it is vitally important, both because it’s legally required and because it’s the right thing to do to protect your customers. But where to begin? Do you need professional assistance – a lawyer or specialized IT firm to accomplish this task? That really depends on the size and nature of your business, the data that requires protection and how much time and energy you are willing to devote to the process. Many businesses are probably capable of accomplishing a lot on their own. For the most part, the regulation is a straightforward recitation of the tasks needed to comply. But is that the best use of your time? Noted author and business consultant Andy Birol would caution business owners to judge very carefully those tasks that they choose to do by themselves and those that are properly delegated. Consider the learning curve required to become proficient in an area that is not a part of your core business. While security is an ongoing and continuous process, monitoring and maintaining a plan is far less cumbersome and time consuming than creating it in the first place. Most businesses will prefer the comfort and efficiency of working with outside professional assistance at least to get the plan created and implemented. Even if you hire professionals, you will still need to be involved in the process. They cannot do it without your participation and that of your senior management and department leaders. And responsibility will not stop there; security needs to be an integral part of your corporate culture from top to bottom, which means it must become the responsibility of everyone in the organization. So pull out the regulation, review it, create an action plan and start in on the list. Otherwise, hire the professionals. Either way, the time is now.
Two men are standing next to each other in a room holding a piece of wood.
October 28, 2024
When do I have to vacate my apartment? Can I leave in the middle of my lease? Can I stay few days longer if I need time before my new space is ready? My landlord says I have to get out before noon on the 31st because he needs time to clean the apartment for the new tenants - can he do that? I am a landlord - can I start showing the apartment before my tenant’s lease is up? Do I have to give notice? Whether you are a landlord or tenant, it is important to know your rights and responsibilities when it comes to ending your lease or occupancy agreement. Under a written lease, the tenant is entitled to occupy the premises until midnight on the last day of the lease; likewise, the tenant is obligated to pay rent through that date. Setting aside various special circumstances (such as active military duty, breach of the lease or other violations by the landlord, or you are a victim of domestic violence) there is no right to leave early unless it was negotiated as part of the written lease. And there is no right to stay longer, just because it might be more convenient. If you are a month-to-month tenant at will, things are little bit different. Either the landlord or tenant can terminate the tenancy, but typically that needs to be done at least a full month in advance. Thus, notice on March 7 would not terminate the tenancy until April 30. And as with the lease, the tenant is entitled to stay until midnight on the final day of the occupancy. Generally speaking, a landlord has the right to enter an apartment to inspect, make repairs and to show prospective tenants. Except in cases of emergency, such as a water leak or fire, this should only be done during normal business hours. Also, as a matter of best practices, it is a good idea for the landlord to contact the tenant and arrange for a mutually convenient time to enter. Tenants do not like surprise visits. But tenants should also understand that there are many circumstances where a landlord cannot easily arrange a visit in advance. The best situation for both landlords and tenants is to do your best to speak with one another and coordinate the end of lease together, in advance. The landlord will want to know as soon as possible when the tenant will be out so that he can get the apartment ready for the next occupant. And tenants want to know that the landlord will not be bothering them needlessly. There is also value in having a brief walk through ahead of time to know if there is damage (even if not caused by the tenant, the landlord wants to know so that he can fix anything before the next tenancy begins), make arrangements for cleaning, trash disposal, and so forth. Of course, as with most legal issues, there are always exceptions to the general rules. For instance, all of this assumes that there are no significant problems—the rent was paid on time, the apartment was in good condition and the parties left each other alone as much as possible.
A city skyline at night with a body of water in the foreground
October 28, 2024
As of this past Monday, the nation’s “most comprehensive data protection law” went into effect, yet many questions remain as to how the regulation will be interpreted and enforced. The law was promulgated by the Office of Consumer Affairs and Business Regulation. While OCABR put it together, the Massachusetts Attorney General is charged with enforcement. As of this writing, I found nothing posted on the AG’s web site that addresses interpretation or enforcement. So business owners and their legal and technical advisors are left to their own best guess. More surprising, many business owners are not even aware of the new law or mistakenly believe that it does not apply to them. For instance, here are several myths surrounding the new law: Myth 1 – “Businesses located out of state do not need to comply.” This is false. The regulation applies to any business wherever located that has access to “Personal Information.” Personal Information, or PI, is a Massachusetts resident’s name in combination with certain identity or financial data, such as a social security number, driver’s license, bank or credit card account number, etc. The regulation does not distinguish between an in-state or out-of-state business. Myth 2 – “The regulation only applies to bigger businesses with several employees and volumes of Personal Information. It doesn’t apply to small Mom and Pop businesses.” This is false. The regulation applies even if you have just one employee or customer as long as you have access to Personal Information. Myth 3 – “I am in a health care or financial services business that is already regulated under federal privacy laws (i.e. HIPAA or GLBA), so we are already covered.” This is false. The federal laws are extensive but they do not perfectly overlap with the Massachusetts regulation. For instance, those laws are geared toward patients and customers, but Massachusetts also includes employees. And the requirements for the written information security plan (WISP) are not identical. That said, there are similarities in the requirements, so an organization that is already comfortable with HIPAA or GLBA probably will not have to do very much to achieve compliance in Massachusetts. In my next article I will explore additional myths.
A city skyline at night with a body of water in the foreground
October 28, 2024
I recently had the opportunity to talk with Nick Fishman, co-founder of EmployeeScreenIQ who interviewed me on the Massachusetts Data Security Regulations and what they mean to businesses. Here's a copy of the interview. Check out the EmployeeScreen blog at https://blog.employeescreen.com/ to learn more about pre-employment screening and the comprehensive methods EmployeeScreenIQ uses to ensure thorough, accurate checks to meet global risk management needs of businesses. EmployeeScreenIQ Podcast with Nick Fishman
A city skyline at night with a body of water in the foreground
October 28, 2024
In my previous article, I discussed the lack of guidance from the Attorney General on implementation and enforcement of the new Massachusetts data security regulation. The law is aimed at protecting residents from identity theft by requiring practically every business with employees or customers in the state to implement a written information security plan (WISP). I also began a list of common misunderstandings relating to the new regulation. Here are a few more myths. Myth 4 – “I have no employees. All payments are processed through a third party service. I never see or handle checks or credit cards so I am not required to have a WISP.” This is probably true. For instance, you could be an Ebay seller who works from home and takes payments only through Paypal. As long as you never have access to any Personal Information (PI), you would be exempt from the regulation. But just a slight change to this scenario requires compliance. A financial planner works from her home and has no employees. Her function is to advise her clients on investments, but clients make their purchases directly from the central office. She never takes any payments directly. But she does receive applications for new accounts when she signs up new customers. The application has the client’s social security numbers and other identifying information. So even if she sends those immediately to the home office, she still has “access” to PI and thus will need to implement a security plan. Myth 5 – “There are so many businesses that are subject to the law and most do not yet have a WISP. The attorney general will never know if we haven’t complied.” This may be true, but are you really willing to risk it? Penalties alone are up to $5000 per violation. You will also be obligated to pay any damages suffered by victims of identity theft. And what about the harm to your reputation? I doubt that the Attorney General or a court would have any sympathy for such a callous disregard for the law that is intentional and willful. On the other hand, a business that may have a security breach, but that can show that they were making a good faith effort to meet industry best practices will probably not be subject to the most severe penalties. According to Scott Schafer Director of the Consumer Protection Division of the Massachusetts Attorney General’s Office, the attorney general will be less likely to bring enforcement actions against businesses that can show that a breach was inadvertent and that they were striving to achieve industry best practices for data protection. Myth 6 – “Our company has implemented state-of-the-art electronic security, including firewalls, antivirus, antimalware and email encryption. Our data is locked down tight and cannot be accessed without double password authentication. Surely we have fulfilled the requirements under the regulation.” This is false. These are certainly important steps toward compliance, but the requirements of the law are much more extensive. To begin with, the regulation applies to both electronic and paper records. As well, companies are required to conduct a review of existing systems and procedures and create and implement a comprehensive written information security plan (WISP). Hopefully this list will help you understand the scope and breadth of the new regulation. If you have not yet started your compliance plan, the place to begin is a review of the regulation and consulting with your legal and technical advisors.
A red and yellow sign with a shadow on a white background.
October 28, 2024
I’d like to think that it’s common knowledge that credit card receipts can be a prime opportunity for identity theft. However, too many of us simply crumple the receipts and throw them in the trash without a care. If the receipt shows your full credit card number and expiration date, this is an invitation for a criminal to go on a shopping spree at your expense. Federal law is intended to help protect against this problem. A few years ago, congress amended the Fair Credit Reporting Act 15 U.S.C. 1681 to require all merchants to truncate credit card numbers on the receipts that they give you at the register. This means that the receipt you receive should not show more than the last 5 digits of the card number. The remaining digits and the expiration date should be unreadable. Even if you threw out this receipt, it would be impossible for an identity thief to use the information. Although this law went into effect in 2006, I occasionally receive receipts that are not in compliance. These are usually the two-part variety – white on top and yellow below, but it can happen even on the type that print out two separate receipts at the time of purchase (one that you sign and return and the other you keep). Earlier this month, I had the pleasure of taking my eldest son on the big college tour – 10 schools in five days. Visiting the schools and the time with my son were terrific; the lengthy drives and staying at a different hotel each night not so much. What was interesting was the receipt I received from one of the major hotel chains where we stayed outside of Washington, DC. To my surprise, this nationally recognized chain provided me with an illegal credit card receipt, showing my full card number and expiration date. Needless to say, I did not toss that one in the trash, but kept it until I got home and could shred it. But imagine how many patrons think nothing of it or simply tell the clerk to just throw it out? I came to learn hotels are apparently the biggest offenders when it comes to data security. Being a maven of sorts on the topic, I happened to see in the March 18 Wall Street Journal that data breaches are heaviest at hotels. According to their sources, 38% of breach investigations in 2009 involved hotels, twice as high as the next highest category. The culprit is typically the point of sale software used to accept payment, much of which is not compliant with Payment Card Industry (PCI) standards. I have sent a complaint to the hotel chain. They are currently investigating my concern. Let’s see what happens.