Connecticut Statutes

§ 42-523 — De-identified and pseudonymous data. Controllers' duties. Exceptions. Applicability of consumers' rights. Disclosure and oversight.

Connecticut·Title 42 Business, Selling, Trading and Collection Practices·Ch. 743jj Data Privacy and Security
(a)Any controller in possession of de-identified data shall:
(1)Take reasonable measures to ensure that the data cannot be associated with an individual;
(2)publicly commit to maintaining and using de-identified data without attempting to re-identify the data; and (3) contractually obligate any recipients of the de-identified data to comply with all provisions of sections 42-515 to 42-525, inclusive.
(b)Nothing in sections 42-515 to 42-525 , inclusive, shall be construed to:
(1)Require a controller or processor to re-identify de-identified data or pseudonymous data; or (2) maintain data in identifiable form, or collect, obtain, retain or access any data or technology, in order to be capable of associating an authenticated consumer request with personal data.
(c)Nothing in sections 42

Free access — add to your briefcase to read the full text and ask questions with AI

Connecticut § 42-523 (De-identified and pseudonymous data. Controllers' duties. Exceptions. Applicability of consumers' rights. Disclosure and oversight.) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Legislative History

(P.A. 22-15, S. 9.) History: P.A. 22-15 effective July 1, 2023.

Nearby Sections

15
View on official source ↗