Latest Post

On June 16, 2021, the Connecticut General Assembly adopted an expanded version of Connecticut’s data breach notification statute (2021 CT H.B. 5310 (NS)). Through this expansion, Connecticut’s data breach notification statute will be updated, effective Oct. 1, 2021, to (1) broaden the definition of “personal information,” (2) shorten the amount of time within which businesses must notify Connecticut residents and the Office of the Attorney General of a data breach, (3) allow for email notice when login credentials are breached, (4) remove the requirement for law enforcement consultation when conducting a risk assessment, and (5) include a HIPAA/HITECH exemption.

What is most notable about Connecticut’s revised data breach notification statute is the omission of a particular provision from the final version of the statute. When the statute was originally introduced to the Connecticut legislature on Jan. 22, 2021, it included an unprecedented provision that would have required entities that suffered data breaches to provide “preliminary substitute notice” of the data breach if the entity was unable to identify and notify affected Connecticut residents within 60 days after the discovery of the incident. The preliminary substitute notice would have consisted of (1) email notice to all affected Connecticut residents whose email addresses were known to the entity; (2) conspicuous posting of the notice on the entity’s website; and (3) notification to major statewide media, including newspapers, radio and television. Even after providing “preliminary substitute notice” of an incident, the entity that suffered the breach would have had to then provide direct notice of the incident to affected Connecticut residents. The final version of the statute, however, does not include this preliminary substitute notice obligation.