Law note · Connecticut

Breach of security re computerized data containing personal information

cite Conn. Gen. Stat. ยง 36a-701b stage IMMINENT commencement not set reviewed 2026-08-27

A person who owns, licenses, or maintains computerized data including personal information must notify each affected Connecticut resident of a breach without unreasonable delay, and no later than 60 days after discovery unless federal law requires a shorter time. 'Personal information' excludes publicly available information lawfully made available to the general public from government records or widely distributed media.

Unlike CTDPA, which bars a private right of action outright, this breach-notification section deems a violation an unfair trade practice under section 42-110b, and CUTPA's own private-action provision, section 42-110g, lets any person who suffers an ascertainable loss from a practice prohibited by section 42-110b sue for damages, so a breach-notice violation carries indirect private-plaintiff exposure that the comprehensive act does not.

This provision is in force under the current codified text; the underlying research did not establish a dated original commencement, so no effective_date is recorded here.

What it asks of an app

  • Notify each affected Connecticut resident of a breach of security involving personal information without unreasonable delay and no later than 60 days after discovery, unless federal law requires a shorter time.
  • Expect a breach-notice violation to expose you to a private suit for damages under CUTPA, section 42-110g, even though CTDPA itself bars a private right of action.

When LexLint raises it

Declared activities: crawls_web, trains_models, deploys_chatbot, automated_outreach

Primary source: official Connecticut statute text, Chapter 669, Connecticut General Statutes

← Back to the example  ·  Lint your app →