Connecticut Statutes

§ 36a-701b — Breach of security re computerized data containing personal information. Notice of breach. Provision of identity theft prevention services and identity theft mitigation services. Delay for criminal investigation. Means of notice. Exemption from public disclosure. Unfair trade practices.

Connecticut § 36a-701b
JurisdictionConnecticut
Title 36aThe Banking Law of Connecticut
Ch. 669Regulated Activities

This text of Connecticut § 36a-701b (Breach of security re computerized data containing personal information. Notice of breach. Provision of identity theft prevention services and identity theft mitigation services. Delay for criminal investigation. Means of notice. Exemption from public disclosure. Unfair trade practices.) is published on Counsel Stack Legal Research, covering Connecticut primary law. Counsel Stack provides free access to over 12 million legal documents including statutes, case law, regulations, and constitutions.

Bluebook
Conn. Gen. Stat. § 36a-701b (2026).

Text

(a)For purposes of this section, (1) “breach of security” means unauthorized access to or unauthorized acquisition of electronic files, media, databases or computerized data, containing personal information when access to the personal information has not been secured by encryption or by any other method or technology that renders the personal information unreadable or unusable; and (2) “personal information” means an individual's (A) first name or first initial and last name in combination with any one, or more, of the following data:
(i)Social Security number;
(ii)taxpayer identification number;
(iii)identity protection personal identification number issued by the Internal Revenue Service;
(iv)driver's license number, state identification card number, passport number, military identi

Free access — add to your briefcase to read the full text and ask questions with AI

Legislative History

(P.A. 05-148, S. 3; 05-288, S. 231, 232; June 12 Sp. Sess. P.A. 12-1, S. 130; P.A. 15-142, S. 6; P.A. 18-90, S. 2; P.A. 19-117, S. 231; 19-196, S. 9; P.A. 21-59, S. 1; P.A. 23-98, S. 4.) History: P.A. 05-148 effective January 1, 2006; P.A. 05-288 made technical changes in Subsecs. (b) and (f), effective January 1, 2006; June 12 Sp. Sess. P.A. 12-1 amended Subsec. (a) by adding “unauthorized” re acquisition, amended Subsec. (b) by designating existing provisions as Subdiv. (1) and amending same to replace “disclose” with “provide notice of” and “disclosure” with “notice” and by adding Subdiv. (2) re notice of breach of security to Attorney General, amended Subsec. (c) by adding “of a resident of this state” re personal information, amended Subsec. (e) by adding “to a resident, owner or licensee” re notice, replacing “person, business or agency” with “person” and making a technical change, and amended Subsec. (f) by replacing references to subject persons with references to residents of this state, owners and licensees, as applicable, adding provisions re notice to Attorney General and deleting reference to system; P.A. 15-142 made technical changes in Subsec. (a), amended Subsec. (b) to replace “was, or is reasonably believed to have been, accessed by an unauthorized person through such breach of security” with “was breached or is reasonably believed to have been breached” and add provision re notice of breach of security not later than 90 days after discovery unless shorter time is required under federal law in Subdiv. (1), to designate existing provision re notice of breach to Attorney General as Subpara. (A) in Subdiv. (2) and amend same to add Subpara. (B) re provision of identity theft prevention services and identity theft mitigation services, and amended Subsec. (c) to replace “was, or is reasonably believed to have been accessed by an unauthorized person” with “was breached or is reasonably believed to have been breached”; P.A. 18-90 amended Subsec. (a)(1) by deleting “account number,” in Subpara. (C), adding Subpara. (D) re financial account number, and making a technical change, and amended Subsec. (b)(2)(B) by replacing “twelve months” with “twenty-four months” re period for which service is to be provided at no cost to resident; P.A. 19-117 amended Subsec. (b)(2)(B) by replacing provision re personal information under Sec. 38a-999b(a)(4)(A) with provision re nonpublic information under Sec. 38a-38(b)(9)(B)(i) and made a conforming change, effective October 1, 2020; P.A. 19-196 changed effective date of P.A. 19-117 from October 1, 2020, to October 1, 2021, effective July 8, 2019; P.A. 21-59 amended Subsec. (a)(2) to redefine “personal information”, redesignate Subpara. (A) as clause (i), Subpara. (B) as clause (iv), Subpara. (C) as clause (v), Subpara. (D) as clause (vi) and added clauses (ii), (iii) and (vii) to (ix) re additional types of personal information in Subpara. (A) and added new Subpara. (B) re user name or electronic mail address; amended Subsec. (b)(1) and (2) to delete provision re conducting business in this state and reference to “ordinary course of such person's business”, amended Subsec. (b)(1) to change 90 days to 60 days, delete provision re completion of investigation by person, add provision regarding notification of additional residents following 60 days after discovery of the breach, delete provision re consultation with law enforcement agencies, and make a technical change, amended Subsec. (b)(2)(B) to replace “nonpublic information” with “personal information” and make a technical change, amended Subsec. (e) to add “, subject to the provisions of subsection (f) of this section”, added new Subsec. (f) re breach of login credentials, redesignated existing Subsec. (f) as Subsec. (g), added Subsec. (h) re persons subject to certain privacy and security standards deemed to be in compliance, added Subsec. (i) re exemption from public disclosure and redesignated existing Subsec. (g) as Subsec. (j); P.A. 23-98 amended Subsec. (a)(2) by redefining “personal information” to include precise geolocation data, amended Subsec. (e)(4) by adding “in the notice provided to the Attorney General”, added Subsec. (k) re deposit of penalties into privacy protection guaranty and enforcement account, and made technical and conforming changes in Subsecs. (a)(2)(A)(viii) and (b)(2)(B).

Nearby Sections

15
View on official source ↗

Cite This Page — Counsel Stack

Bluebook (online)
Connecticut § 36a-701b, Counsel Stack Legal Research, https://law.counselstack.com/statute/ct/36a-701b.