Privacy Law Library

Breach of Security Involving Computerized Personal Information (data breach notification)

CT Breach Notification

Breach notification · Data security

Requires anyone holding computerized personal information of Connecticut residents to notify affected residents and the Attorney General of a breach of unencrypted data within 60 days of discovery. Where Social Security or taxpayer ID numbers are exposed, the data owner must offer at least two years of free identity theft prevention services.

Where
Connecticut
Citation
Conn. Gen. Stat. 36a-701b
Status
In force
In force since
2006-01-01
Last amended
2023-10-01
Enforced by
Connecticut Attorney General (Conn. Gen. Stat. 36a-701b(j))
People can sue
No
Penalties
Failure to comply is an unfair trade practice under CUTPA enforced by the Attorney General (36a-701b(j)); CUTPA civil penalties are up to $5,000 per wilful violation (42-110o). Penalties may go to the privacy protection guaranty and enforcement account (36a-701b(k)).
Applies to
  • Any person that owns, licenses or maintains computerized data including personal information of Connecticut residents (36a-701b(b)-(c))
  • Personal information: name plus SSN, ITIN, IRS IP PIN, driver's license, passport, military or other government ID, card number, financial account number with access code, medical information, health insurance ID, biometric data, or (since 2023-10-01) precise geolocation data; or a user name or email with password or security Q&A (36a-701b(a)(2))

Breach duties

  • Notify affected Connecticut residents without unreasonable delay and no later than 60 days after discovering a breach, unless a risk-of-harm investigation determines no likely harm; notify later-identified residents as expediently as possible.Conn. Gen. Stat. 36a-701b(b)(1)
  • Notify the Attorney General no later than when residents are notified.Conn. Gen. Stat. 36a-701b(b)(2)(A)
  • Offer affected residents whose SSN or taxpayer ID number was breached at least 24 months of free identity theft prevention (and, if applicable, mitigation) services, with enrollment and credit-freeze information.Conn. Gen. Stat. 36a-701b(b)(2)(B)
  • A person maintaining data it does not own must notify the owner or licensee immediately after discovering a breach.Conn. Gen. Stat. 36a-701b(c)
  • Notice may be written, telephonic, electronic or (if cost exceeds $250,000, the class exceeds 500,000, or contact data are lacking) substitute notice; login-credential breaches may be noticed electronically with a prompt to change passwords.Conn. Gen. Stat. 36a-701b(e)-(f)

Other duties

  • Entities complying with HIPAA/HITECH or a GLBA functional regulator's breach rules are deemed compliant if they also notify the Attorney General when residents are notified.Conn. Gen. Stat. 36a-701b(g)-(h)

Sources

Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.

Research reference, not legal advice.