The Connecticut data breach notification law, codified at General Statutes § 36a-701b, requires any business that holds computerized personal information of Connecticut residents to notify affected individuals and the state Attorney General within 60 days of discovering a breach, offer at least 24 months of free identity theft prevention services when Social Security or taxpayer identification numbers are involved, and face civil penalties under the Connecticut Unfair Trade Practices Act for failing to comply.1Justia. Connecticut Code 36a-701b – Breach of Security re Computerized Data Containing Personal Information
What Data Triggers the Notification Duty
The statute is triggered when a resident’s first name (or first initial) and last name are exposed together with any of the following:
- Social Security number, taxpayer identification number, IRS identity protection PIN, driver’s license or state ID number, passport number, or military ID number
- Credit or debit card number, or a financial account number combined with a security code, access code, or password that would allow access to the account
- Medical information about a person’s history, condition, or treatment, or a health insurance policy or subscriber ID number
- Biometric data such as fingerprints, voiceprints, or retina images used for identity verification
- Precise geolocation data as defined by the Connecticut Data Privacy Act
A separate category covers a username or email address paired with a password or security question that would unlock an online account. This one stands on its own; the person’s name does not need to be attached.1Justia. Connecticut Code 36a-701b – Breach of Security re Computerized Data Containing Personal Information
A “breach of security” means unauthorized access to or acquisition of electronic files, databases, or computerized data containing this personal information, where the data was not protected by encryption or another method that rendered it unreadable.
The 60-Day Deadline
Once a breach is discovered, notice to affected residents must go out no later than 60 days after discovery. If a federal law imposes a shorter deadline, the federal deadline controls. The Attorney General must be notified no later than the time residents are notified, and in practice most businesses submit the AG report first or at the same time using the state’s online submission form.2Office of the Attorney General. Reporting a Data Breach
A law enforcement agency can request that notification be delayed if issuing it would impede a criminal investigation. The delay lasts only as long as law enforcement determines is necessary, and the organization must send notices once told that doing so will no longer compromise the investigation.1Justia. Connecticut Code 36a-701b – Breach of Security re Computerized Data Containing Personal Information
If additional affected residents are identified after the 60-day window closes, the organization must proceed in good faith to notify them as expediently as possible. The statute does not set a hard second deadline, but the Attorney General can review that timing after the fact.
What the Notice Must Say
When a breach involves a Social Security number or taxpayer identification number, the organization must offer affected residents free identity theft prevention and mitigation services for at least 24 months. The notice must include everything a resident needs to enroll, along with instructions on how to place a credit freeze.1Justia. Connecticut Code 36a-701b – Breach of Security re Computerized Data Containing Personal Information The Attorney General’s office has confirmed the 24-month floor applies specifically to breaches of these two data types.2Office of the Attorney General. Reporting a Data Breach
For breaches involving other categories, such as driver’s license numbers, financial account data, or medical records, the statute does not require a specific duration of identity theft services. Businesses often offer them anyway, but the 24-month rule is tied exclusively to Social Security and taxpayer ID numbers.
When the breach involves online login credentials, the notice can be delivered electronically and should direct the resident to change the compromised password immediately. It should also warn the resident to update any other accounts where they reused the same credentials.
How the Notice Can Be Delivered
Notices may be delivered by written mail, telephone, or electronic communication if the resident previously consented to electronic notices under federal e-signature standards.
Substitute notice is allowed only if the organization demonstrates to the Attorney General that individual notice would cost more than $250,000, the affected group exceeds 500,000 people, or the organization lacks sufficient contact information. Substitute notice is not one action but three: email to any affected individuals whose email addresses the organization has, conspicuous posting on the organization’s website, and notification to major statewide newspaper, radio, and television outlets.1Justia. Connecticut Code 36a-701b – Breach of Security re Computerized Data Containing Personal Information
When Notice Is Not Required
Two situations excuse the notification obligation. The first is encryption. If the compromised data was properly encrypted and the encryption key was not also exposed, the event does not count as a breach under the statute. If both the encrypted data and the key were accessed, the event is treated as though the data was never encrypted at all.
The second is the harm exception. Even when unencrypted personal information is exposed, notification is not required if the organization conducts an appropriate investigation and reasonably determines the breach is not likely to result in harm to the affected individuals. This is not a casual out. The organization must actually investigate and document its reasoning, and the Attorney General’s office can scrutinize that analysis later.1Justia. Connecticut Code 36a-701b – Breach of Security re Computerized Data Containing Personal Information
Who Has to Comply
Any person or business that owns, licenses, or maintains computerized data containing the personal information of Connecticut residents is covered. Size does not matter. A five-person accounting firm has the same obligation as a multinational corporation.
Vendors that hold data on behalf of another organization are also covered. If a third-party vendor experiences the breach, the vendor must notify the data owner, and the data owner must notify affected residents and the Attorney General.
HIPAA and GLBA Safe Harbors
Organizations subject to HIPAA and the HITECH Act are deemed compliant with the Connecticut law so long as they follow their federal notification obligations. There is a catch: these entities must still notify the Connecticut Attorney General no later than when they notify residents, if AG notification would otherwise be required under state law.
A parallel provision covers financial institutions regulated by a primary federal regulator under the Gramm-Leach-Bliley Act. They satisfy the state law by following the breach procedures their federal regulator has established, but they too must notify the Connecticut Attorney General when notice goes to state residents. The safe harbor removes duplicative procedures, not the state notification itself.1Justia. Connecticut Code 36a-701b – Breach of Security re Computerized Data Containing Personal Information
Penalties for Noncompliance
The Attorney General enforces § 36a-701b through the Connecticut Unfair Trade Practices Act. A failure to comply with the notification requirements is treated as an unfair trade practice.2Office of the Attorney General. Reporting a Data Breach
For willful violations, the Attorney General can seek a civil penalty of up to $5,000 per violation. A willful violation means the party knew or should have known its conduct violated the law.3Connecticut General Assembly. Chapter 735a – Unfair Trade Practices In a breach affecting thousands of residents, per-violation penalties can accumulate quickly.
The statute does not give individual residents the right to sue a business directly for failing to notify them. Enforcement rests with the Attorney General. Residents can file complaints with the AG’s office, but they cannot bring their own civil lawsuits under § 36a-701b. A breach could still support other legal claims, such as negligence or a broader CUTPA consumer protection claim, but those are separate theories with their own elements.
Overlapping Obligations to Watch
Two other regimes can apply to the same incident, and satisfying § 36a-701b does not satisfy either of them.
The Connecticut Data Privacy Act, in effect since 2023, requires data controllers to maintain reasonable administrative, technical, and physical data security practices appropriate to the volume and nature of the personal data they handle. The CTDPA also requires data processors to assist controllers in meeting their breach notification obligations under § 36a-701b, so vendor contracts should spell out those responsibilities.4Connecticut General Assembly. Chapter 743jj – Data Privacy and Security
Publicly traded Connecticut businesses have a separate federal duty. When a company determines a cybersecurity incident is material, it must file an Item 1.05 disclosure on Form 8-K within four business days of that determination. Materiality is assessed using both quantitative factors, such as financial losses, and qualitative ones, such as reputational harm, regulatory exposure, or damage to customer relationships.5U.S. Securities and Exchange Commission. Disclosure of Cybersecurity Incidents Determined To Be Material and Other Cybersecurity Incidents The state’s 60-day window and the SEC’s four-day window run on separate tracks.