EnglishEspañol
Connecticut flag

Connecticut

Connecticut Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 7 primary sources cited on this page. How we verify our legal content

Connecticut Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Frequently Asked Questions

How quickly must a business report a data breach in Connecticut?

Connecticut requires notification to affected residents and the Attorney General without unreasonable delay and no later than 60 days after discovering the breach, under Conn. Gen. Stat. 36a-701b. Sixty days is the outer limit, not a target. Notice can be delayed if a law enforcement agency requests it because notification would impede a criminal investigation, and notice is not required at all if the data was encrypted, if a safe harbor in subsection (g) or (h) applies, or if the entity reasonably determines after an appropriate investigation that the breach will not likely result in harm.

Does Connecticut require credit monitoring after a data breach?

Yes, but only when the breach involves Social Security numbers or taxpayer identification numbers. In those cases, the breached entity must offer at least 24 months of free identity theft prevention services and credit monitoring. The entity must also provide information about how to place a credit freeze.

Is there an encryption safe harbor under Connecticut breach notification law?

Yes. If the personal information was encrypted or rendered unreadable or unusable by another method at the time of the breach, notification is not required. However, if the encryption key was also compromised, the safe harbor does not apply and the entity must notify affected residents and the Attorney General.

Can individuals sue for breach notification failures in Connecticut?

Not under the breach notification statute itself, which creates no private cause of action. Subsection (j) of Conn. Gen. Stat. 36a-701b makes a violation an unfair trade practice under CUTPA and provides that it shall be enforced by the Attorney General, who can seek civil penalties up to $5,000 per willful violation, injunctive relief, and restitution. Because the violation is a CUTPA practice, however, Conn. Gen. Stat. 42-110g(a) independently allows a person who suffers an ascertainable loss to sue for actual damages, so private CUTPA claims built on a notification failure are commonly pleaded and their viability is unsettled.

Does Connecticut include geolocation data in its breach notification law?

Yes. As of October 1, 2023, precise geolocation data is included in the definition of personal information under Conn. Gen. Stat. 36a-701b. Connecticut is one of a small number of states that specifically includes geolocation data as a trigger for breach notification. A breach involving a resident's name combined with their precise geolocation data requires the same notification as a breach involving Social Security numbers or financial account information.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected the Connecticut breach notification guide to add the statute's risk-of-harm exemption from notice, describe the subsection (g) own-policy and financial-institution safe harbors accurately, fix the description of where civil penalties go and who administers that account, and replace the flat "no private right of action" statement with the unsettled CUTPA picture.

Updated the SB 117 forensic-reporting section to reflect that the bill passed the Senate but died in the House without becoming law (no October 1, 2026 mandate took effect), and corrected two wording errors in the law-enforcement-delay and health-insurance-identifier provisions to match the current text of Conn. Gen. Stat. 36a-701b.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Governing law re-checked for recent changes

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Conn. Gen. Stat. 36a-701b(cga.ct.gov).gov
  2. CT AG: Reporting a Data Breach(portal.ct.gov).gov
  3. CT AG Data Breach Report Form(portal.ct.gov).gov
  4. CT AG: Privacy and Data Security(portal.ct.gov).gov
  5. Conn. Gen. Stat. 4e-70(cga.ct.gov).gov
  6. CT AG 2025 CTDPA Enforcement Report(portal.ct.gov).gov
  7. SB 117 (2026)(cga.ct.gov).gov
  8. Conn. Gen. Stat. 36a-701b: breach of security re computerized data containing personal information (subsection (b)(1) risk-of-harm exemption, (g) own-policy and regulator safe harbors, (h) HIPAA/HITECH safe harbor, (j) CUTPA unfair trade practice, (k) penalty deposit)(cga.ct.gov)
  9. Conn. Gen. Stat. 42-472a: privacy protection guaranty and enforcement account, a nonlapsing General Fund account used by the Commissioner of Consumer Protection(cga.ct.gov)
  10. Conn. Gen. Stat. 42-110g: CUTPA action for damages by any person suffering an ascertainable loss, class actions, costs and attorney fees (and 42-110o civil penalties up to $5,000 per wilful violation)(cga.ct.gov)
Share: