Connecticut
Connecticut Data Breach Notification Laws: Reporting Rules & Timelines (2026)
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 7 primary sources cited on this page. How we verify our legal content

Connecticut law requires businesses that discover a data breach to notify affected residents and the state Attorney General without unreasonable delay and no later than 60 days after discovery, under Conn. Gen. Stat. 36a-701b. Encrypted data that is breached does not trigger this obligation unless the encryption key was also compromised.
Connecticut has one of the more detailed data breach notification laws in the United States. Codified at Conn. Gen. Stat. 36a-701b, the law requires any person or business that owns, licenses, or maintains computerized data containing personal information to notify affected Connecticut residents and the state Attorney General after discovering a security breach.
The law has been amended several times since its original enactment in 2005, most recently expanding the definition of personal information to include precise geolocation data (effective October 1, 2023). A 60-day outer notification deadline, mandatory credit monitoring, and an encryption safe harbor make this one of the more prescriptive breach notification statutes in the country.
For a broader look at Connecticut's overall privacy framework, see the parent guide to Connecticut Data Privacy Laws.
Who Must Comply With the Law

The statute applies to any person who conducts business in Connecticut and owns, licenses, or maintains computerized data that includes personal information of Connecticut residents. This covers corporations, LLCs, sole proprietors, nonprofit organizations, and government agencies.
Third-party service providers that maintain data on behalf of another entity have a separate obligation. They must notify the data owner immediately upon discovering a breach so the data owner can fulfill its notification duties.
State contractors who handle confidential information from government agencies face additional requirements under a companion statute, Conn. Gen. Stat. 4e-70, which imposes minimum security standards and its own breach reporting obligations to both the contracting agency and the Attorney General.
What Qualifies as Personal Information
Connecticut defines personal information in two categories that trigger notification obligations.
Category 1: Name Plus Sensitive Data Element
An individual's first name or first initial and last name combined with any one or more of:
- Social Security number or taxpayer identification number
- IRS identity protection PIN
- Driver's license number, state ID number, passport number, military ID, or other government-issued identification commonly used to verify identity
- Credit or debit card number
- Financial account number in combination with any required security code, access code, or password
- Medical information, including any information regarding an individual's medical history, mental or physical condition, or medical treatment or diagnosis
- Health insurance policy number, subscriber identification number, or any unique identifier used by a health insurer
- Biometric data generated by electronic measurements of an individual's unique physical characteristics, such as fingerprints, voiceprints, or retina and iris images
- Precise geolocation data (added October 1, 2023)
Category 2: Online Account Credentials
A username or email address combined with a password or security question and answer that would permit access to an online account. Name is not required for this category to trigger notification.
Exclusions
Publicly available information lawfully made available from federal, state, or local government records is excluded from the definition of personal information.
What Constitutes a Breach of Security
Under the statute, a "breach of security" means unauthorized access to or acquisition of electronic files, media, databases, or computerized data containing personal information when access to the personal information has not been secured by encryption or by any other method or technology that renders the personal information unreadable or unusable.
This definition has two important features. First, it focuses on unauthorized access or acquisition rather than just acquisition alone. Second, it builds in the encryption safe harbor directly, meaning encrypted data that is breached does not trigger notification unless the encryption key was also compromised.
The 60-Day Notification Timeline

Connecticut sets an outer limit of 60 days. Entities must provide notice to affected residents without unreasonable delay and not later than 60 days after discovery of the breach. If a shorter timeline applies under federal law, the federal requirement controls.
Risk-of-Harm Exemption
The 60-day clock only matters if notice is required at all. The final sentence of subsection (b)(1) provides that notification "shall not be required if, after an appropriate investigation the person reasonably determines that the breach will not likely result in harm to the individuals whose personal information has been acquired or accessed."
This is a distinct exemption, separate from the encryption safe harbor and from the law enforcement delay described below. It excuses notice entirely rather than postponing it. Two conditions are built into its own text: an appropriate investigation must actually happen, and the determination that harm is unlikely must be a reasonable one, which in practice means documenting the analysis at the time the decision is made.
When the Clock Starts
The 60-day period begins at the moment the entity discovers the breach, not when it completes its investigation. This is stricter than states that start the clock after an investigation concludes.
Late-Discovered Victims
If additional affected residents are identified after the initial 60-day window, the entity must notify those individuals "as expediently as possible" in good faith. There is no specific secondary deadline, but the "as expediently as possible" standard has teeth under CUTPA enforcement.
Law Enforcement Delay
The notification deadline may be extended if a law enforcement agency determines that notification would impede a criminal investigation and requests the delay. The delay lasts only as long as law enforcement requests it.
Attorney General Notification
Every entity that discovers a breach must notify the Connecticut Attorney General no later than the time notice is provided to affected residents. There is no minimum number of affected individuals required to trigger AG notification. Even a breach affecting a single Connecticut resident requires AG notice.
The AG's office provides an online breach report submission form as the preferred method for reporting. After submission, the reporting entity receives a confirmation email followed by a case number in the format PR plus seven digits. Updates or supplements to a previously reported breach should be emailed to ag.breach@ct.gov with the case number.
Credit Monitoring and Identity Theft Services

Connecticut goes beyond basic notification by requiring affirmative identity protection services. When a breach involves Social Security numbers or taxpayer identification numbers, the breached entity must:
- Offer identity theft prevention services at no cost to the affected resident
- Offer identity theft mitigation services if applicable
- Provide these services for a minimum of 24 months
- Include information on how the resident can place a credit freeze on their credit file
This 24-month credit monitoring mandate is longer than what many states require. Several states impose 12-month minimums, and others leave it to the breached entity's discretion entirely.
How Notice Must Be Provided
The statute permits several methods of direct notice:
- Written notice sent to the individual's postal address
- Telephone notice delivered directly to the individual
- Electronic notice that complies with the federal E-SIGN Act (15 U.S.C. 7001 et seq.)
For breaches involving online account credentials (username/email plus password), the entity must direct the resident to change their password and security questions. If the breach involved the individual's email account, notification cannot be sent to that compromised email address. The entity must use another verified contact method instead.
Substitute Notice
Substitute notice is available when the cost of direct notification would exceed $250,000, the affected class exceeds 500,000 people, or the entity lacks sufficient contact information. Substitute notice requires all three of:
- Email notice to all affected individuals for whom the entity has an email address
- Conspicuous posting on the entity's website
- Notification to major statewide media outlets
Encryption Safe Harbor
Connecticut provides a clear encryption safe harbor. If the personal information involved in the breach was encrypted or secured by another method that renders it unreadable or unusable, the breach notification requirements do not apply. However, if the encryption key was also compromised in the breach, the safe harbor does not protect the entity, and notification is required.
Compliance Safe Harbors
The statute lets several categories of entity be deemed in compliance without following its own notice mechanics. The conditions attached to each are not the same, and the differences matter:
- HIPAA-covered entities: Compliance with the Health Insurance Portability and Accountability Act (HIPAA) and the Health Information Technology for Economic and Clinical Health Act (HITECH) satisfies Connecticut's breach notification requirements. Subsection (h) is the safe harbor that carries both conditions: the entity must still notify the Connecticut Attorney General no later than when it notifies affected residents, and it must still comply with the identity theft services requirement in subsection (b)(2)(B) when Social Security numbers or taxpayer identification numbers are involved.
- Financial institutions: Under subsection (g), an entity that maintains breach procedures under the rules, regulations, procedures, or guidelines established by its primary or functional regulator, as defined in 15 U.S.C. 6809(2), is deemed in compliance. That covers the federal banking agencies' interagency guidance issued under the Gramm-Leach-Bliley Act. Subsection (g) attaches only two conditions: notify residents, owners, and licensees as the regulator's rules require, and notify the Attorney General no later than when notice goes to the resident. Unlike the HIPAA safe harbor, it does not carry the identity theft services condition.
- Entities with their own breach procedures: Subsection (g) opens with a general safe harbor that is not limited to regulated industries. Any person who maintains their own security breach procedures as part of an information security policy for the treatment of personal information, and who otherwise complies with this section's timing requirements, is deemed in compliance, provided they notify residents, owners, and licensees in accordance with their own policies and, where a resident is notified, also notify the Attorney General no later than the time notice is provided to that resident.
Enforcement Under CUTPA
Failure to comply with any provision of 36a-701b constitutes an unfair trade practice under the Connecticut Unfair Trade Practices Act (CUTPA, Conn. Gen. Stat. 42-110a et seq.). This means the Attorney General can pursue:
- Civil penalties up to $5,000 per willful violation
- Injunctive relief ordering the entity to comply
- Restitution to affected consumers
- Disgorgement of profits gained through the violation
Subsection (k) provides that civil penalties collected for failure to comply with this section may be deposited into the privacy protection guaranty and enforcement account established under Conn. Gen. Stat. 42-472a. The deposit is permissive rather than mandatory. That account is a nonlapsing account within the General Fund, and 42-472a(a) directs that it be used by the Commissioner of Consumer Protection, not by the Attorney General's office, for reimbursing individuals injured by violations of the sections it lists and for enforcement of those sections.
The notification statute itself creates no private cause of action. Subsection (j) says only that a failure to comply constitutes an unfair trade practice for purposes of Conn. Gen. Stat. 42-110b and "shall be enforced by the Attorney General," which is the statute's express remedy.
One step removed, the picture is less settled. Because subsection (j) declares a violation a CUTPA unfair trade practice, and because Conn. Gen. Stat. 42-110g(a) independently allows any person who suffers an ascertainable loss from a practice prohibited by 42-110b to sue for actual damages, with class actions available under 42-110g(b) and attorney's fees under 42-110g(d), private CUTPA claims predicated on breach notification failures are commonly pleaded. Whether such a claim survives is unsettled, and secondary summaries of the 2021 amendment describe the consequence differently. The safe reading is that AG enforcement is the certain exposure and a derivative CUTPA suit is a live risk, not a foreclosed one.
Recent Enforcement Activity
The Connecticut Attorney General has actively enforced data security and privacy obligations. In 2025, the office finalized a $200,000 settlement with PharMerica over a breach affecting 105,000 Connecticut residents and a $200,000 settlement with WebTPA Employer Services. While these actions were brought under the broader CTDPA framework, they demonstrate the AG's willingness to pursue significant penalties for data security failures.
How This Law Interacts With the CTDPA
Connecticut's breach notification statute (36a-701b) and the Connecticut Data Privacy Act (CTDPA, Conn. Gen. Stat. 42-515 et seq.) are separate but complementary laws.
The breach notification statute governs what happens after a security incident. It tells entities when to notify, whom to notify, and what services to offer. The CTDPA governs ongoing data privacy obligations including consent requirements, consumer rights, data minimization, and data protection assessments.
A single data incident could trigger obligations under both laws. For example, a breach of biometric data would require notification under 36a-701b (because biometric data is personal information) and could also expose CTDPA violations if the entity lacked proper consent or security measures for that biometric data in the first place.
2026 Forensic Reporting Bill: SB 117 Passed the Senate but Died in the House
Connecticut's 2026 legislative session considered Senate Bill 117, which would have amended 36a-701b to require mandatory forensic examination and reporting for large-scale breaches. Key provisions of the bill as passed by the Senate included:
- A new category called a "massive breach of security" affecting 100,000 or more Connecticut residents
- Mandatory retention of a qualified third-party forensic examiner immediately upon discovery
- Submission of the forensic report to the Attorney General within 90 days of discovery
- If the entity fails to comply, the AG can hire a forensic firm directly and bill the entity
- Civil penalties up to $500,000 (or $100,000 for small businesses) on top of existing CUTPA penalties
SB 117 passed the Senate as amended on April 29, 2026, and was transmitted to the House, where it was tabled for the House calendar on April 30, 2026. The House did not take a floor vote before Connecticut's 2026 regular session adjourned in early May, so the bill died without becoming law. No Public Act was enacted, and the proposed October 1, 2026 forensic-reporting mandate did not take effect. The bill could be reintroduced in a future legislative session.
Disclaimer
This article provides general legal information about Connecticut data breach notification requirements and is not legal advice. Laws and regulations change frequently, and their application varies based on specific circumstances. Consult a qualified attorney licensed in Connecticut for guidance on your particular situation.
More Connecticut Laws
Frequently Asked Questions
How quickly must a business report a data breach in Connecticut?
Connecticut requires notification to affected residents and the Attorney General without unreasonable delay and no later than 60 days after discovering the breach, under Conn. Gen. Stat. 36a-701b. Sixty days is the outer limit, not a target. Notice can be delayed if a law enforcement agency requests it because notification would impede a criminal investigation, and notice is not required at all if the data was encrypted, if a safe harbor in subsection (g) or (h) applies, or if the entity reasonably determines after an appropriate investigation that the breach will not likely result in harm.
Does Connecticut require credit monitoring after a data breach?
Yes, but only when the breach involves Social Security numbers or taxpayer identification numbers. In those cases, the breached entity must offer at least 24 months of free identity theft prevention services and credit monitoring. The entity must also provide information about how to place a credit freeze.
Is there an encryption safe harbor under Connecticut breach notification law?
Yes. If the personal information was encrypted or rendered unreadable or unusable by another method at the time of the breach, notification is not required. However, if the encryption key was also compromised, the safe harbor does not apply and the entity must notify affected residents and the Attorney General.
Can individuals sue for breach notification failures in Connecticut?
Not under the breach notification statute itself, which creates no private cause of action. Subsection (j) of Conn. Gen. Stat. 36a-701b makes a violation an unfair trade practice under CUTPA and provides that it shall be enforced by the Attorney General, who can seek civil penalties up to $5,000 per willful violation, injunctive relief, and restitution. Because the violation is a CUTPA practice, however, Conn. Gen. Stat. 42-110g(a) independently allows a person who suffers an ascertainable loss to sue for actual damages, so private CUTPA claims built on a notification failure are commonly pleaded and their viability is unsettled.
Does Connecticut include geolocation data in its breach notification law?
Yes. As of October 1, 2023, precise geolocation data is included in the definition of personal information under Conn. Gen. Stat. 36a-701b. Connecticut is one of a small number of states that specifically includes geolocation data as a trigger for breach notification. A breach involving a resident's name combined with their precise geolocation data requires the same notification as a breach involving Social Security numbers or financial account information.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected the Connecticut breach notification guide to add the statute's risk-of-harm exemption from notice, describe the subsection (g) own-policy and financial-institution safe harbors accurately, fix the description of where civil penalties go and who administers that account, and replace the flat "no private right of action" statement with the unsettled CUTPA picture.
Updated the SB 117 forensic-reporting section to reflect that the bill passed the Senate but died in the House without becoming law (no October 1, 2026 mandate took effect), and corrected two wording errors in the law-enforcement-delay and health-insurance-identifier provisions to match the current text of Conn. Gen. Stat. 36a-701b.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Governing law re-checked for recent changes
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Connecticut General Statutes, Title 36a (The Banking Law of Connecticut), Chapter 669
§ 36a-701bBreach of security re computerized data containing personal information. Notice of breach. Provision of identity theft prevention services and identity theft mitigation services. Delay for criminal investigation. Means of notice. Exemption from public disclosure. Unfair trade practices.In forcecited in 2 of our articles
(a) For purposes of this section, (1) “breach of security” means unauthorized access to or unauthorized acquisition of electronic files, media, databases or computerized data, containing personal information when access to the personal information has not been secured by encryption or by any other method or technology that renders the personal information unreadable or unusable; and (2) “personal information” means an individual's (A) first name or first initial and last name in combination with any one, or more, of the following data: (i) Social Security number; (ii) taxpayer identification number; (iii) identity protection personal identification number issued by the Internal Revenue Service; (iv) driver's license number, state identification card number, passport number, military identification number or other identification number issued by the government that is commonly used to verify identity; (v) credit or debit card number; (vi) financial account number in combination with any required security code, access code or password that would permit access to such financial account; (vii) medical information regarding an individual's medical history, mental or physical condition,…
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at cga.ct.gov
Cited in 3 court opinions in our collectionLatest citing opinion in our collection: 2019
Opinions citing this section in our collection:
- Recall Total Infomation Management, Inc. v. Federal Insurance Co. (Connecticut Appellate Court 2014, 147 Conn. App. 450)“…Law § 899-aa (2) (McKinney 2005); and one in Connecticut; General Statutes § 36a-701b; both of which require certain actions…”
- In re Target Corp. Customer Data Security Breach Litigation (District Court, D. Minnesota 2014, 66 F. Supp. 3d 1154)“…of the statute “shall be enforced by the Attorney General.” Conn. Gen.Stat. § 36a-701b(g). As with Arkansas, this language cle…”
- In re Equifax, Inc. (District Court, N.D. Georgia 2019, 362 F. Supp. 3d 1295)“…Pls.' Br. in Opp'n to Defs.' Mot. to Dismiss, at 63. Conn. Gen. Stat. § 36a-701b(g) (emphasis added). See Targe…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Connecticut Data Privacy Laws: CTDPA Consumer Rights Guide (2026)
Connecticut General Statutes, Title 04e (State Contracting), Chapter 62a
§ 4e-70Requirements for state contractors who receive confidential information. Definitions. Minimum requirements. Prohibitions. Breach. Violation. Ban. Effect on other applicable laws.In force
(a) As used in this section and section 4e-71: (1) “Contractor” means an individual, business or other entity that is receiving confidential information from a state contracting agency or agent of the state pursuant to a written agreement to provide goods or services to the state. (2) “State agency” means any agency with a department head, as defined in section 4-5. (3) “State contracting agency” means any state agency disclosing confidential information to a contractor pursuant to a written agreement with such contractor for the provision of goods or services for the state.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at cga.ct.gov
United States Code Title 15
§ 7001General rule of validityIn forcecited in 18 of our articles
Notwithstanding any statute, regulation, or other rule of law (other than this subchapter and subchapter II), with respect to any transaction in or affecting interstate or foreign commerce— a signature, contract, or other record relating to such transaction may not be denied legal effect, validity, or enforceability solely because it is in electronic form; and a contract relating to such transaction may not be denied legal effect, validity, or enforceability solely because an electronic signature or electronic record was used in its formation. This subchapter does not— limit, alter, or otherwise affect any requirement imposed by a statute, regulation, or rule of law relating to the rights and obligations of persons under such statute, regulation, or rule of law other than a requirement that contracts or other records be written, signed, or in nonelectronic form; or require any person to agree to use or accept electronic records or electronic signatures, other than a governmental agency with respect to a record other than a contract to which it is a party.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at uscode.house.gov
Cited in 132 court opinions in our collectionLatest citing opinion in our collection: 2026
In the courts (editorial summary, independently checked):Metropolitan Regional Information Systems v. American Home Realty Network (2012) applied 15 U.S.C. 7001(a) to hold an electronic assignment process satisfied the signed writing requirement of Copyright Act 204(a). Blatt v. Capital One Auto Finance (2017) held 7001(c) disclosures were not required where the record was delivered on paper.
Opinions citing this section in our collection:
- Metropolitan Regional Information Systems, Inc. v. American Home Realty Network, Inc. (District Court, D. Maryland 2012, 904 F. Supp. 2d 530)✓Subscribers assigned photo copyrights to a real estate database by uploading images under online terms of use; the court relied on E-SIGN, 15 U.S.C. section 7001, to hold those electronic assignments met the Copyright Act signed-writing rule, and denied reconsideration.
- Cutrone v. Mortgage Electronic Registration Systems, Inc. (District Court, E.D. New York 2013, 981 F. Supp. 2d 144)✓Homeowners sued MERS in state court over a second mortgage recording tax on an E-Sign mortgage; MERS removed under 15 U.S.C. section 7001, but the court held that statute gives no private right of action and at most a federal defense, which cannot support removal, and remanded.
- Blatt v. Capital One Auto Finance, Inc. (District Court, M.D. Tennessee 2017, 237 F. Supp. 3d 688)“…legal effect ..solely because it is in electronic form[.]” 15 U.S.C. § 7001 (a)(1).. Furthermore, it mandates that…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Mississippi Data Breach Notification Laws: Reporting Rules & Timelines (2026), Mississippi Data Privacy Laws: Breach Notification & Consumer Rights (2026), Montana Data Privacy Laws: MCDPA Consumer Rights Guide (2026)
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Conn. Gen. Stat. 36a-701b(cga.ct.gov).gov
- CT AG: Reporting a Data Breach(portal.ct.gov).gov
- CT AG Data Breach Report Form(portal.ct.gov).gov
- CT AG: Privacy and Data Security(portal.ct.gov).gov
- Conn. Gen. Stat. 4e-70(cga.ct.gov).gov
- CT AG 2025 CTDPA Enforcement Report(portal.ct.gov).gov
- SB 117 (2026)(cga.ct.gov).gov
- Conn. Gen. Stat. 36a-701b: breach of security re computerized data containing personal information (subsection (b)(1) risk-of-harm exemption, (g) own-policy and regulator safe harbors, (h) HIPAA/HITECH safe harbor, (j) CUTPA unfair trade practice, (k) penalty deposit)(cga.ct.gov)
- Conn. Gen. Stat. 42-472a: privacy protection guaranty and enforcement account, a nonlapsing General Fund account used by the Commissioner of Consumer Protection(cga.ct.gov)
- Conn. Gen. Stat. 42-110g: CUTPA action for damages by any person suffering an ascertainable loss, class actions, costs and attorney fees (and 42-110o civil penalties up to $5,000 per wilful violation)(cga.ct.gov)